Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.6
CVE-2025-71364: picklescan - Remote Code Execution via Malicious Pickle Files
CVE-2025-71364
CVE-2025-71364
Summary
An outdated version of picklescan can execute arbitrary code if it loads a malicious pickle file. This means an attacker could potentially take control of the system by sending a specially crafted file. Update picklescan to the latest version to prevent this.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| picklescan | picklescan | < 0.0.30 |
Original title
picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. Attackers can craft malicious pic...
Original description
picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle reduce methods, allowing remote code execution. Attackers can craft malicious pickle files embedding this built-in function that evade detection but execute arbitrary commands when loaded.
mitre CVSS3.1
8.1
Vulnerability type
CWE-502
Deserialization of Untrusted Data
Published: 4 Jul 2026 · Updated: 23 Jul 2026 · First seen: 4 Jul 2026