← Vulnerability feed

Vulnerability record · CVE-2025-71348 · published 21 June 2026

CVE-2025-71348: Mmaitre314 picklescan deserialization of untrusted data vulnerability

MMmaitre314 · Picklescan

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply chain attacks.

7.6 CVSS 4.0 High EPSS 0.55% · top 56.0% CWE-502 · Deserialization of untrusted data
7.6CVSS 4.0 base score
0.55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
26 Jun 2026Last modified by NVD

Description

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply chain attacks.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-71348 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2025-10157Mmaitre314 picklescan vulnerabilityA Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsa…EPSS 0.79%9.3CVE-2025-10156Mmaitre314 picklescan vulnerabilityAn Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker …EPSS 1.5%9.3CVE-2025-10155Mmaitre314 picklescan improper input validation vulnerabilityAn Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacke…EPSS 0.85%7.6CVE-2025-71357Mmaitre314 picklescan deserialization of untrusted data vulnerabilitypicklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can…EPSS 0.39%7.6CVE-2025-71378Mmaitre314 picklescan deserialization of untrusted data vulnerabilitypicklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. …EPSS 0.48%6.9CVE-2026-56304Mmaitre314 picklescan deserialization of untrusted data vulnerabilitypicklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte file…EPSS 0.44%6.8CVE-2025-46417Mmaitre314 picklescan vulnerabilityThe unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deseria…EPSS 0.22%5.3CVE-2025-1945Mmaitre314 picklescan insufficient verification of data authenticity vulnerabilitypicklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag bits are modified. By flippi…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2025-71348), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.