Arbitrary Code Execution Vulnerability in Picklescan by Maitre314
CVE-2025-71365
7.6HIGH
What is CVE-2025-71365?
Picklescan, prior to version 0.0.33, is vulnerable to an arbitrary code execution vulnerability. The issue lies in its failure to detect malicious pickle files capable of invoking the numpy.f2py.crackfortran.myeval function. Attackers can exploit this flaw by crafting pickle files that contain embedded arbitrary code, which can evade detection by Picklescan, allowing remote code execution upon loading. Users are advised to upgrade to the latest version to mitigate this risk.
Affected Version(s)
picklescan 0 < 0.0.33
picklescan 0.0.33
