CVE-2025-71351
HIGHpicklescan - Remote Code Execution via timeit.timeit() Detection Bypass
Title source: cnaDescription
picklescan before 0.0.25 fails to detect malicious pickle files that use timeit.timeit() in the __reduce__ method, allowing remote code execution. Attackers can craft pickle files that import dangerous libraries like os and execute arbitrary system commands, which evade picklescan detection and execute when pickle.load() is called.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GHSA Advisory GHSA-v7x6-rv5q-mhwc
https://github.com/mmaitre314/picklescan/security/advisories/GHSA-v7x6-rv5q-mhwc
Third Party Advisory third-party-advisory
VulnCheck Advisory: picklescan - Remote Code Execution via timeit.timeit() Detection Bypass
https://www.vulncheck.com/advisories/picklescan-remote-code-execution-via-timeit-timeit-detection-bypass
Scores
CVSS v4
7.6
EPSS
0.0071
EPSS Percentile
49.9%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-184
Status
published
Products (2)
picklescan/picklescan
< 0.0.25
picklescan/picklescan
0.0.25
Published
Jun 21, 2026
Tracked Since
Jun 21, 2026