CVE-2025-71373
HIGHpicklescan - Remote Code Execution via operator.methodcaller Detection Bypass
Title source: cnaDescription
picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads using operator.methodcaller that execute arbitrary code when loaded, compromising systems relying on picklescan for validation.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-x843-g5mx-g377)
https://github.com/mmaitre314/picklescan/security/advisories/GHSA-x843-g5mx-g377
Third Party Advisory third-party-advisory
VulnCheck Advisory: picklescan - Remote Code Execution via operator.methodcaller Detection Bypass
https://www.vulncheck.com/advisories/picklescan-remote-code-execution-via-operator-methodcaller-detection-bypass
Scores
CVSS v3
8.1
EPSS
0.0044
EPSS Percentile
36.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-693
Status
published
Products (2)
picklescan/picklescan
< 0.0.33
picklescan/picklescan
0.0.33
Published
Jul 04, 2026
Tracked Since
Jul 04, 2026