---
id: CVE-2025-71339
aliases:
  - GHSA-6556-fwc2-fg2p
  - PYSEC-2026-1783
title: >-
  Picklescan is vulnerable to RCE through missing detection when calling
  numpy.f2py.crackfortran._eval_length
summary: >-
  Picklescan is vulnerable to RCE through missing detection when calling
  numpy.f2py.crackfortran._eval_length
severity: medium
vendor: picklescan
product: picklescan
ecosystem: pip
affected:
  - picklescan < 0.0.33
patched:
  - picklescan 0.0.33
published: '2025-12-30'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-6556-fwc2-fg2p'
references:
  - url: >-
      https://github.com/mmaitre314/picklescan/security/advisories/GHSA-6556-fwc2-fg2p
  - url: 'https://github.com/mmaitre314/picklescan/pull/53'
  - url: >-
      https://github.com/mmaitre314/picklescan/commit/70c1c6c31beb6baaf52c8db1b6c3c0e84a6f9dab
  - url: 'https://github.com/mmaitre314/picklescan'
  - url: 'https://github.com/mmaitre314/picklescan/releases/tag/v0.0.33'
tags:
  - osv
  - pip
epss: 0.00523
epssPercentile: 0.41953
ingestedAt: '2026-07-08T18:25:46.286Z'
---

## Overview

### Summary

Picklescan uses the `numpy.f2py.crackfortran._eval_length` function (a NumPy F2PY helper) to execute arbitrary Python code during unpickling.

### Details

Picklescan fails to detect a malicious pickle that uses the gadget `numpy.f2py.crackfortran._eval_length` in `__reduce__`, allowing arbitrary command execution when the pickle is loaded. A crafted object returns this function plus attacker‑controlled arguments; the scan reports the file as safe, but pickle.load() triggers execution.

### PoC
```python
class PoC:
    def __reduce__(self):
        from numpy.f2py.crackfortran import _eval_length
        return _eval_length, ("__import__('os').system('whoami')", None)
```

### Impact

- Arbitrary code execution on the victim machine once they load the “scanned as safe” pickle / model file.
- Affects any workflow relying on Picklescan to vet untrusted pickle / PyTorch artifacts.
- Enables supply‑chain poisoning of shared model files.

### Credits
- [ac0d3r](https://github.com/ac0d3r)
- [Tong Liu](https://lyutoon.github.io), Institute of information engineering, CAS

## Affected packages

- `picklescan < 0.0.33`

## Remediation

Upgrade to a patched release:

- `picklescan 0.0.33`
