Remote Code Execution Vulnerability in Picklescan by Maitre314
CVE-2025-71370
7.6HIGH
What is CVE-2025-71370?
The identified vulnerability in Picklescan prior to version 0.0.28 enables attackers to create malicious pickle files that exploit the torch.jit.unsupported_tensor_ops.execWrapper function. When these files are processed through pickle.load(), they can subvert security measures and execute arbitrary code. This flaw poses significant risks, allowing unauthorized actions and potential compromise of affected systems.
Affected Version(s)
picklescan 0 < 0.0.28
picklescan 0.0.28
