← Vulnerability feed

Vulnerability record · CVE-2025-10155 · published 17 September 2025

CVE-2025-10155: Mmaitre314 picklescan improper input validation vulnerability

MMmaitre314 · Picklescan

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the pickle file incorrectly considered safe is loaded, it can lead to the execution of malicious code.

9.3 CVSS 4.0 Critical EPSS 0.85% · top 43.6% CWE-20 · Improper input validation
9.3CVSS 4.0 base score
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
26 Sep 2026Last modified by NVD

Description

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the pickle file incorrectly considered safe is loaded, it can lead to the execution of malicious code.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-10155 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2025-10157Mmaitre314 picklescan vulnerabilityA Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsa…EPSS 0.79%9.3CVE-2025-10156Mmaitre314 picklescan vulnerabilityAn Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker …EPSS 1.5%7.6CVE-2025-71357Mmaitre314 picklescan deserialization of untrusted data vulnerabilitypicklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can…EPSS 0.39%7.6CVE-2025-71378Mmaitre314 picklescan deserialization of untrusted data vulnerabilitypicklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. …EPSS 0.48%7.6CVE-2025-71348Mmaitre314 picklescan deserialization of untrusted data vulnerabilitypicklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. At…EPSS 0.55%6.9CVE-2026-56304Mmaitre314 picklescan deserialization of untrusted data vulnerabilitypicklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte file…EPSS 0.44%6.8CVE-2025-46417Mmaitre314 picklescan vulnerabilityThe unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deseria…EPSS 0.22%5.3CVE-2025-1945Mmaitre314 picklescan insufficient verification of data authenticity vulnerabilitypicklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag bits are modified. By flippi…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2025-10155), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.