Arbitrary Code Execution Vulnerability in Picklescan by Maitre314
CVE-2025-71365

7.6HIGH

Key Information:

Vendor

Picklescan

Vendor
CVE Published:
23 June 2026

What is CVE-2025-71365?

Picklescan, prior to version 0.0.33, is vulnerable to an arbitrary code execution vulnerability. The issue lies in its failure to detect malicious pickle files capable of invoking the numpy.f2py.crackfortran.myeval function. Attackers can exploit this flaw by crafting pickle files that contain embedded arbitrary code, which can evade detection by Picklescan, allowing remote code execution upon loading. Users are advised to upgrade to the latest version to mitigate this risk.

Affected Version(s)

picklescan 0 < 0.0.33

picklescan 0.0.33

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CoolwindHF
.