CVE-2025-71325

CRITICAL

picklescan - Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw

Title source: cna
STIX 2.1

Description

picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allowing malicious pickle files to bypass detection. Attackers can craft pickle files with arguments at position zero to trigger unexpected exceptions and evade security scanning.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
GHSA Advisory GHSA-9gvj-pp9x-gcfr
https://github.com/mmaitre314/picklescan/security/advisories/GHSA-9gvj-pp9x-gcfr
Third Party Advisory third-party-advisory
VulnCheck Advisory: picklescan - Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw
https://www.vulncheck.com/advisories/picklescan-detection-bypass-via-stack-global-opcode-parsing-logic-flaw

Scores

CVSS v3 9.8
EPSS 0.0047
EPSS Percentile 37.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-391
Status published
Products (3)
picklescan/picklescan < 0.0.27
picklescan/picklescan 0.0.27
pypi/picklescan 0 - 0.0.27PyPI
Published Jun 17, 2026
Tracked Since Jun 17, 2026