Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.6

CVE-2025-71375: picklescan - Malicious Code Evades Detection in Pickle Files

CVE-2025-71375 CVE-2025-71375
Summary

picklescan versions before 0.0.34 can't detect certain malicious code in pickle files. This allows attackers to sneak in malicious code that can execute without being caught. Update to the latest version of picklescan to ensure detection of all types of malicious code.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
picklescan picklescan < 0.0.34
Original title
picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.me...
Original description
picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load().
mitre CVSS3.1 8.1
Vulnerability type
CWE-502 Deserialization of Untrusted Data
Published: 4 Jul 2026 · Updated: 23 Jul 2026 · First seen: 4 Jul 2026