Arbitrary File Writing Vulnerability in Picklescan by Mmaitre314
CVE-2025-71321

9.3CRITICAL

Key Information:

Vendor

Picklescan

Vendor
CVE Published:
17 June 2026

What is CVE-2025-71321?

Picklescan versions prior to 0.0.33 are susceptible to an arbitrary file writing vulnerability. Attackers can exploit this flaw by using the distutils.file_util.write_file method to bypass the application's blocklist. By constructing deceptive pickle objects, malicious users can overwrite essential system files, potentially leading to denial of service or even executing code remotely, posing significant security threats to affected systems.

Affected Version(s)

picklescan 0 < 0.0.33

picklescan 0.0.33

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0x-Apollyon
.