CVE-2025-71363
HIGHpicklescan - Arbitrary Code Execution via Undetected cProfile.run in Pickle Deserialization
Title source: cnaDescription
picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files with cProfile.run payloads that bypass picklescan detection and achieve code execution upon deserialization.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-49gj-c84q-6qm9)
https://github.com/mmaitre314/picklescan/security/advisories/GHSA-49gj-c84q-6qm9
Third Party Advisory third-party-advisory
VulnCheck Advisory: picklescan - Arbitrary Code Execution via Undetected cProfile.run in Pickle Deserialization
https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-undetected-cprofile-run-in-pickle-deserialization
Scores
CVSS v3
8.1
EPSS
0.0059
EPSS Percentile
44.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-502
Status
published
Products (2)
picklescan/picklescan
< 0.0.30
picklescan/picklescan
0.0.30
Published
Jun 30, 2026
Tracked Since
Jul 01, 2026