Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.6

CVE-2025-71366: picklescan before 0.0.28: Malicious Code Can Run Without Detection

CVE-2025-71366 CVE-2025-71366
Summary

picklescan, a tool for detecting malicious code in pickle files, has a flaw before version 0.0.28. This means attackers can sneak in malicious code that won't be caught, allowing them to run arbitrary code on your system. Update to the latest version of picklescan to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
picklescan picklescan < 0.0.28
Original title
picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to bypass safety checks. Remote attackers can embe...
Original description
picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to bypass safety checks. Remote attackers can embed undetected code in pickle files to achieve arbitrary code execution when victims load the files.
mitre CVSS3.1 8.1
Vulnerability type
CWE-502 Deserialization of Untrusted Data
Published: 4 Jul 2026 · Updated: 23 Jul 2026 · First seen: 4 Jul 2026