CVE-2025-71359
HIGHpicklescan - Unsafe Deserialization via lib2to3.pgen2.grammar.Grammar.loads
Title source: cnaDescription
picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method, allowing remote code execution. Attackers can craft pickle files embedding dangerous code that evades picklescan detection and executes during pickle.load() deserialization.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-f54q-57x4-jg88)
https://github.com/mmaitre314/picklescan/security/advisories/GHSA-f54q-57x4-jg88
Third Party Advisory third-party-advisory
VulnCheck Advisory: picklescan - Unsafe Deserialization via lib2to3.pgen2.grammar.Grammar.loads
https://www.vulncheck.com/advisories/picklescan-unsafe-deserialization-via-lib2to3-pgen2-grammar-grammar-loads
Scores
CVSS v3
8.1
EPSS
0.0043
EPSS Percentile
35.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-502
Status
published
Products (2)
picklescan/picklescan
< 0.0.29
picklescan/picklescan
0.0.29
Published
Jul 04, 2026
Tracked Since
Jul 04, 2026