Junglewise Threat Intelligence

CVE-2025-10157: mmaitre314 PickleScan protection bypass via subclass imports

CVE-2025-10157 · Severity: high · CVSS 8.3 · Published 2025-09-10

Technologies: picklescan (PyPI). Vendors: PyPI.

Executive brief

PickleScan is a security tool used to scan Python pickle files and AI models for malicious code. A vulnerability in its scanning logic allows attackers to bypass security checks by using specific module naming techniques. If a user scans a specially crafted malicious model, the tool may fail to detect the threat, potentially leading to the execution of unauthorized code on the user's system.

Technical details

PickleScan (up to version 0.0.30) is vulnerable to a protection mechanism failure (CWE-693) in its unsafe globals check. The scanner performs a strict string match against full module names in its '_unsafe_globals' list. Attackers can bypass this by using submodules or subclasses of dangerous imports (e.g., specific sub-events in 'asyncio') that do not exactly match the blocked strings. This allows malicious pickle payloads to be flagged as 'Suspicious' rather than 'Dangerous' or blocked entirely. An attacker can exploit this by distributing crafted PyTorch models or ZIP archives containing malicious pickle files. The issue is fixed in version 0.0.31 by implementing more robust module and submodule matching logic.

Affected products

  • mmaitre314 picklescan <= 0.0.30

Timeline

  • 2025-09-08: disclosed: Advisory published by maintainer
  • 2025-09-10: advisory: GitHub Advisory published
  • 2025-09-10: patched: Version 0.0.31 released

References

Related threats