CVE-2025-10155High· 7.8▾ TwilightAn Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTo…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the pickle file incorrectly considered safe is loaded, it can lead to the execution of malicious code.
picklescan < 0.0.31Upgrade past the affected range:
picklescan 0.0.31Connected by shared product, vendor, weakness, or advisory.
CVE-2025-10157High· 7.8A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check
CVE-2025-10156Critical· 9.8An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans
GHSA-g7vj-qw6x-g3p8Critical· 9.8Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist
GHSA-q8qp-8jq6-78mcHigh· 8.1Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
GHSA-gq8p-2329-gh3xHigh· 8.1Duplicate Advisory: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
GHSA-mg57-j93w-g3c7High· 8.1Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx