Scanning Bypass Vulnerability in Picklescan by Mmaitre314
CVE-2026-53875
7.1HIGH
What is CVE-2026-53875?
The Picklescan tool prior to version 1.0.3 is vulnerable to a scanning bypass that enables attackers to exploit its scan_pytorch function. By using the reduce function, attackers can inject malicious magic numbers, crafting PyTorch payloads that intelligently evade detection. This vulnerability permits arbitrary code execution once these payloads are loaded with torch.load(), posing serious security risks.
Affected Version(s)
picklescan 0 < 1.0.3
picklescan 1.0.3
