Executive brief
PickleScan is a security tool used to scan Python pickle files and AI models for malicious code. A vulnerability in its scanning logic allows attackers to bypass security checks by using specific module naming techniques. If a user scans a specially crafted malicious model, the tool may fail to detect the threat, potentially leading to the execution of unauthorized code on the user's system.
Technical details
PickleScan (up to version 0.0.30) is vulnerable to a protection mechanism failure (CWE-693) in its unsafe globals check. The scanner performs a strict string match against full module names in its '_unsafe_globals' list. Attackers can bypass this by using submodules or subclasses of dangerous imports (e.g., specific sub-events in 'asyncio') that do not exactly match the blocked strings. This allows malicious pickle payloads to be flagged as 'Suspicious' rather than 'Dangerous' or blocked entirely. An attacker can exploit this by distributing crafted PyTorch models or ZIP archives containing malicious pickle files. The issue is fixed in version 0.0.31 by implementing more robust module and submodule matching logic.
Affected products
- mmaitre314 picklescan <= 0.0.30
Timeline
- 2025-09-08: disclosed: Advisory published by maintainer
- 2025-09-10: advisory: GitHub Advisory published
- 2025-09-10: patched: Version 0.0.31 released