GHSA-gq8p-2329-gh3xHigh· 8.1▾ TwilightDuplicate Advisory: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-7cq8-mj8x-j263. This link is maintained to preserve external references.
picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.autocomplete.AutoComplete.fetch_completions in reduce methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when loaded by victims.
picklescan < 0.0.29Upgrade to a patched release:
picklescan 0.0.29Connected by shared product, vendor, weakness, or advisory.
CVE-2025-71376High· 8.1Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
GHSA-q8qp-8jq6-78mcHigh· 8.1Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
GHSA-mg57-j93w-g3c7High· 8.1Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx
GHSA-x36p-c636-788xHigh· 8.1Duplicate Advisory: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
GHSA-8mc5-7w9m-fqv6High· 8.1Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
GHSA-fcqg-3mwf-cfcfHigh· 8.1Duplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx