Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.6

CVE-2025-71373: picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads usi...

CVE-2025-71373 CVE-2025-71373
Summary

picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads using operator.methodcaller that execute arbitrary code when loaded, compromising systems relying on pickl...

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
picklescan picklescan < 0.0.33
Original title
picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads usi...
Original description
picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads using operator.methodcaller that execute arbitrary code when loaded, compromising systems relying on picklescan for validation.
mitre CVSS3.1 8.1
Vulnerability type
CWE-693 Protection Mechanism Failure
Published: 4 Jul 2026 · Updated: 23 Jul 2026 · First seen: 4 Jul 2026