CVE-2025-71357

HIGH

picklescan - Arbitrary Code Execution via Undetected idlelib.pyshell.ModifiedInterpreter.runcommand

Title source: cna
STIX 2.1

Description

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GHSA Advisory GHSA-j343-8v2j-ff7w
https://github.com/mmaitre314/picklescan/security/advisories/GHSA-j343-8v2j-ff7w
Third Party Advisory third-party-advisory
VulnCheck Advisory: picklescan - Arbitrary Code Execution via Undetected idlelib.pyshell.ModifiedInterpreter.runcommand
https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-undetected-idlelib-pyshell-modifiedinterpreter-runcommand

Scores

CVSS v3 8.1
EPSS 0.0028
EPSS Percentile 19.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-502
Status published
Products (3)
mmaitre314/picklescan < 0.0.30
picklescan/picklescan < 0.0.30
picklescan/picklescan 0.0.30
Published Jun 21, 2026
Tracked Since Jun 21, 2026