---
id: CVE-2025-71366
title: >-
  picklescan before 0.0.28 fails to detect malicious
  torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files,
  allowing attackers to bypass safety checks
summary: >-
  picklescan before 0.0.28 fails to detect malicious
  torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files,
  allowing attackers to bypass safety checks. Remote attackers can embed
  undetected code in pickle files to ach…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-502
published: '2026-07-04'
updated: '2026-07-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-71366'
references:
  - url: >-
      https://github.com/mmaitre314/picklescan/security/advisories/GHSA-4r9r-ch6f-vxmx
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-torch-utils-bottleneck-main-run-cprofile
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00638
epssPercentile: 0.48474
ingestedAt: '2026-07-04T21:57:46.848Z'
---

## Overview

picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle files, allowing attackers to bypass safety checks. Remote attackers can embed undetected code in pickle files to achieve arbitrary code execution when victims load the files.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
