Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.6
CVE-2025-71369: picklescan - Malicious Code Execution via Pickle Files
CVE-2025-71369
CVE-2025-71369
Summary
picklescan before version 0.0.28 fails to detect malicious pickle files, which can be exploited by attackers to execute malicious code remotely. This vulnerability affects the safety of picklescan when handling pickle files. To stay secure, update picklescan to the latest version.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| picklescan | picklescan | < 0.0.28 |
Original title
picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing attackers to bypass safety checks. Remote...
Original description
picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing attackers to bypass safety checks. Remote attackers can embed undetected malicious code in pickle files that executes during deserialization, enabling remote code execution.
mitre CVSS3.1
8.1
Vulnerability type
CWE-502
Deserialization of Untrusted Data
Published: 4 Jul 2026 · Updated: 23 Jul 2026 · First seen: 4 Jul 2026