Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.6
CVE-2025-71372: Picklescan - Malicious Pickle Files Can Execute Arbitrary Code
CVE-2025-71372
CVE-2025-71372
Summary
Picklescan, a tool for detecting malicious pickle files, has a flaw in versions before 0.0.33. This means attackers can create fake pickle files that execute unauthorized code when loaded, which can be used to compromise shared models. To stay safe, update to the latest version of Picklescan.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| picklescan | picklescan | < 0.0.33 |
Original title
Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files th...
Original description
Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded, bypassing Picklescan's safety checks and enabling supply-chain poisoning of shared model files.
mitre CVSS3.1
8.1
Vulnerability type
CWE-502
Deserialization of Untrusted Data
Published: 4 Jul 2026 · Updated: 23 Jul 2026 · First seen: 4 Jul 2026