Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.6

CVE-2025-71364: picklescan - Remote Code Execution via Malicious Pickle Files

CVE-2025-71364 CVE-2025-71364
Summary

An outdated version of picklescan can execute arbitrary code if it loads a malicious pickle file. This means an attacker could potentially take control of the system by sending a specially crafted file. Update picklescan to the latest version to prevent this.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
picklescan picklescan < 0.0.30
Original title
picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. Attackers can craft malicious pic...
Original description
picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. Attackers can craft malicious pickle files embedding this built-in function that evade detection but execute arbitrary commands when loaded.
mitre CVSS3.1 8.1
Vulnerability type
CWE-502 Deserialization of Untrusted Data
Published: 4 Jul 2026 · Updated: 23 Jul 2026 · First seen: 4 Jul 2026