Junglewise Threat Intelligence

CVE-2025-10155: mmaitre314 Picklescan protection mechanism failure via file extension mismatch

CVE-2025-10155 · Severity: high · CVSS 7.8 · Published 2025-09-10

Technologies: picklescan (PyPI). Vendors: PyPI.

Executive brief

Picklescan, a tool used to detect malicious code in machine learning models and data files, can be bypassed by simply changing a file's extension. An attacker can disguise a dangerous file using a PyTorch-related extension (like .bin), causing the scanner to skip its security checks. This could allow malicious code to be executed on a user's system when they load what they believe to be a safe, scanned model.

Technical details

A vulnerability in the `scan_bytes` function of `picklescan/scanner.py` allows attackers to bypass security scans by using mismatched file extensions. The scanner prioritizes PyTorch-specific parsing logic if a file has a PyTorch-related extension (e.g., .bin, .pt). If the file is actually a standard pickle file, the PyTorch parser fails and returns an error immediately without falling back to standard pickle analysis. This logic flaw allows malicious pickle files to bypass detection entirely. The issue is addressed in version 0.0.31 by ensuring the scanner always attempts a standard pickle scan as a fallback regardless of the file extension or initial parsing failures.

Affected products

  • mmaitre314 picklescan <= 0.0.30

Timeline

  • 2025-09-08: disclosed
  • 2025-09-10: advisory
  • 2025-09-10: patched: Version 0.0.31 released

References

Related threats