Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2025-71365: picklescan may run hidden code in malicious files
CVE-2025-71365 · published 3 months ago
Summary
The picklescan tool (versions before 0.0.33) can miss specially crafted pickle files that contain hidden code. When such a file is opened, the hidden code can be executed on the system. Update picklescan to the latest version or use alternative scanning methods to prevent this.
What to do
- Update matthieu maitre picklescan to version 0.0.33.
- Update picklescan to version 0.0.33.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| pip | matthieu maitre | picklescan |
< 0.0.33 Fix: upgrade to 0.0.33
|
| pip | – | picklescan |
< 0.0.33 Fix: upgrade to 0.0.33
|
Original advisory text
picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.myeval Detection Bypass
picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.myeval function through the reduce method. Attackers can craft malicious pickle files embedding arbitrary code that evades picklescan detection and executes remote code when loaded.
References
- https://github.com/mmaitre314/picklescan/pull/53 URL
- https://github.com/mmaitre314/picklescan/commit/70c1c6c31beb6baaf52c8db1b6c3c0e8... URL
- https://nvd.nist.gov/vuln/detail/CVE-2025-71365 Vendor Advisory
- https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-num... Vendor Advisory
- https://github.com/mmaitre314/picklescan/security/advisories/GHSA-3329-ghmp-jmv5 Vendor Advisory
- https://github.com/mmaitre314/picklescan Product
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71365... Vendor Advisory
- https://pypi.org/project/picklescan Product
- https://github.com/advisories/GHSA-3329-ghmp-jmv5 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-94Code Injection
CWE-502Deserialization of Untrusted Data
Timeline
Published23 Jun 2026
Updated2 Oct 2026
First seen6 Mar 2026
Sources
GHSA-3329-ghmp-jmv5 · GHSA
CVE-2025-71365 · NVD
GHSA-3329-ghmp-jmv5 · OSV
PYSEC-2026-4131 · OSV
CVE-2025-71365 · OSV
Track software like this
Free during beta