- Description
- picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection and execute remote code when loaded via pickle.load().
- Source
- disclosure@vulncheck.com
- NVD status
- Analyzed
- Products
- picklescan
CVSS 4.0
- Type
- Secondary
- Base score
- 7.6
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
- disclosure@vulncheck.com
- CWE-502
- Hype score
- Not currently trending
picklescan told you the .pkl file was safe. It lied. CVE-2025-71378 is a scanner bypass that lets attackers hide code execution in Python pickle files. Here's what to check Today:
@disismohi
22 Jun 2026
63 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2025-71378 Arbitrary Code Execution in picklescan Before 0.0.30 via cProfile.runctx https://t.co/dck7Ai8gqq
@VulmonFeeds
21 Jun 2026
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🟠 HIGH (CVSS 8.1) — CVE-2025-71378 Published: 2026-06-21 picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection and execute remot
@CVE2026COIN
21 Jun 2026
35 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D8DD7A91-0138-4CAC-95B5-FA9EEA0ECE30",
"versionEndExcluding": "0.0.30",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]