{"id":"CVE-2025-71339","aliases":["GHSA-6556-fwc2-fg2p","PYSEC-2026-1783"],"title":"Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length","summary":"Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length","severity":"medium","vendor":"picklescan","product":"picklescan","ecosystem":"pip","affected":["picklescan < 0.0.33"],"patched":["picklescan 0.0.33"],"published":"2025-12-30","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-6556-fwc2-fg2p","references":[{"url":"https://github.com/mmaitre314/picklescan/security/advisories/GHSA-6556-fwc2-fg2p"},{"url":"https://github.com/mmaitre314/picklescan/pull/53"},{"url":"https://github.com/mmaitre314/picklescan/commit/70c1c6c31beb6baaf52c8db1b6c3c0e84a6f9dab"},{"url":"https://github.com/mmaitre314/picklescan"},{"url":"https://github.com/mmaitre314/picklescan/releases/tag/v0.0.33"}],"tags":["osv","pip"],"epss":0.00523,"epssPercentile":0.41953,"ingestedAt":"2026-07-08T18:25:46.286Z","slug":"CVE-2025-71339","body":"## Overview\n\n### Summary\n\nPicklescan uses the `numpy.f2py.crackfortran._eval_length` function (a NumPy F2PY helper) to execute arbitrary Python code during unpickling.\n\n### Details\n\nPicklescan fails to detect a malicious pickle that uses the gadget `numpy.f2py.crackfortran._eval_length` in `__reduce__`, allowing arbitrary command execution when the pickle is loaded. A crafted object returns this function plus attacker‑controlled arguments; the scan reports the file as safe, but pickle.load() triggers execution.\n\n### PoC\n```python\nclass PoC:\n    def __reduce__(self):\n        from numpy.f2py.crackfortran import _eval_length\n        return _eval_length, (\"__import__('os').system('whoami')\", None)\n```\n\n### Impact\n\n- Arbitrary code execution on the victim machine once they load the “scanned as safe” pickle / model file.\n- Affects any workflow relying on Picklescan to vet untrusted pickle / PyTorch artifacts.\n- Enables supply‑chain poisoning of shared model files.\n\n### Credits\n- [ac0d3r](https://github.com/ac0d3r)\n- [Tong Liu](https://lyutoon.github.io), Institute of information engineering, CAS\n\n## Affected packages\n\n- `picklescan < 0.0.33`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `picklescan 0.0.33`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}