Arbitrary File Writing Vulnerability in Picklescan by Mmaitre314
CVE-2025-71321
9.3CRITICAL
What is CVE-2025-71321?
Picklescan versions prior to 0.0.33 are susceptible to an arbitrary file writing vulnerability. Attackers can exploit this flaw by using the distutils.file_util.write_file method to bypass the application's blocklist. By constructing deceptive pickle objects, malicious users can overwrite essential system files, potentially leading to denial of service or even executing code remotely, posing significant security threats to affected systems.
Affected Version(s)
picklescan 0 < 0.0.33
picklescan 0.0.33
