CVE-2025-71341

HIGH

picklescan - Remote Code Execution via Undetected profile.Profile.runctx

Title source: cna
STIX 2.1

Description

picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using profile.Profile.runctx in the reduce method to achieve remote code execution when the pickle file is loaded.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-6vqj-c2q5-j97w)
https://github.com/mmaitre314/picklescan/security/advisories/GHSA-6vqj-c2q5-j97w
Third Party Advisory third-party-advisory
VulnCheck Advisory: picklescan - Remote Code Execution via Undetected profile.Profile.runctx
https://www.vulncheck.com/advisories/picklescan-remote-code-execution-via-undetected-profile-profile-runctx

Scores

CVSS v3 8.1
EPSS 0.0047
EPSS Percentile 38.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-502
Status published
Products (2)
picklescan/picklescan < 0.0.29
picklescan/picklescan 0.0.29
Published Jun 23, 2026
Tracked Since Jun 23, 2026