CVE-2025-71349

HIGH

picklescan - Arbitrary Code Execution via Undetected trace.Trace.run in Pickle Files

Title source: cna
STIX 2.1

Description

picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using trace.Trace.run in the reduce method to achieve arbitrary code execution when pickle.load processes the file.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-5qwp-399c-mjwf)
https://github.com/mmaitre314/picklescan/security/advisories/GHSA-5qwp-399c-mjwf
Third Party Advisory third-party-advisory
VulnCheck Advisory: picklescan - Arbitrary Code Execution via Undetected trace.Trace.run in Pickle Files
https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-undetected-trace-trace-run-in-pickle-files

Scores

CVSS v3 8.1
EPSS 0.0056
EPSS Percentile 43.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-502
Status published
Products (2)
picklescan/picklescan < 0.0.29
picklescan/picklescan 0.0.29
Published Jun 30, 2026
Tracked Since Jul 01, 2026