picklescan vulnerabilities
CVEs whose affected-version data names the picklescan package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
56 CVEsRSS
CVE-2025-10157High· 7.8A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check
A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check. This is possible because the scanner performs an exact match for modul…
CVE-2025-10156Critical· 9.8An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans
An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans. This is achieved by crafting a ZIP archive containing a file w…
CVE-2025-10155High· 7.8An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTo…
An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTo…
CVE-2025-71378MediumPicklescan is missing detection when calling built-in Python cProfile.runctx
Picklescan is missing detection when calling built-in Python cProfile.runctx
CVE-2025-71357HighPicklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
CVE-2025-71344MediumPicklescan is missing detection when calling built-in python ensurepip._run_pip
Picklescan is missing detection when calling built-in python ensurepip._run_pip
CVE-2025-71374MediumPicklescan has a missing detection when calling built-in python profile.Profile.run
Picklescan has a missing detection when calling built-in python profile.Profile.run
CVE-2025-71352MediumPicklescan has a missing detection when calling built-in python trace.Trace.runctx
Picklescan has a missing detection when calling built-in python trace.Trace.runctx
CVE-2025-71368MediumPicklescan is missing detection when calling built-in python doctest.debug_script
Picklescan is missing detection when calling built-in python doctest.debug_script
CVE-2025-71371MediumPicklescan has a missing detection when calling built-in python code.InteractiveInterpreter
Picklescan has a missing detection when calling built-in python code.InteractiveInterpreter
CVE-2025-71361MediumPicklescan has a missing detection when calling built-in python idlelib.calltip.Calltip
Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip
CVE-2025-71376High· 8.1Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
CVE-2025-71358MediumPicklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity
Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity
CVE-2025-71341High· 8.1Picklescan has a missing detection when calling built-in python profile.Profile.runctx
Picklescan has a missing detection when calling built-in python profile.Profile.runctx
CVE-2025-71349MediumPicklescan has a missing detection when calling built-in python trace.Trace.run
Picklescan has a missing detection when calling built-in python trace.Trace.run
CVE-2025-71363MediumPicklescan is missing detection when calling built-in python cProfile.run
Picklescan is missing detection when calling built-in python cProfile.run
CVE-2025-71354MediumPicklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem
Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem
CVE-2025-71340MediumPicklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode
Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode
CVE-2025-71348High· 8.1Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config
Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config
CVE-2025-71370High· 8.1Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
CVE-2025-71350MediumPicklescan missing detection when calling pytorch function torch.utils.collect_env.run
Picklescan missing detection when calling pytorch function torch.utils.collect_env.run
CVE-2025-71325HighPicklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
CVE-2025-71351MediumPicklescan missing detection when calling built-in python library function timeit.timeit()
Picklescan missing detection when calling built-in python library function timeit.timeit()
CVE-2025-71355MediumPicklescan failed to detect to some unsafe global function in Numpy library
Picklescan failed to detect to some unsafe global function in Numpy library
CVE-2025-46417HighPicklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
CVE-2025-1716Critical· 9.8PoCpicklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft …
picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and include a malicious pickle file with a non-standard file exte…