Junglewise Threat Intelligence

CVE-2025-71325: picklescan detection bypass in STACK_GLOBAL opcode parsing

CVE-2025-71325 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: picklescan (PyPI). Vendors: PyPI.

Executive brief

picklescan is a security tool used to scan Python pickle files and AI models for malicious code. A flaw in how the tool parses specific data structures allows attackers to craft malicious files that crash the scanner or bypass its security checks entirely. This could allow dangerous code to be uploaded to platforms like Hugging Face or executed on local systems without being detected by the scanner.

Technical details

A parsing logic error exists in the `_list_globals` function of picklescan (and modelscan) when handling the `STACK_GLOBAL` opcode. The scanner fails to track arguments in the correct range (specifically ignoring arguments at position zero), which causes it to find an unexpected number of values. An attacker can craft a malicious pickle file that triggers an unhandled exception during this parsing process, causing the scanner to fail and allowing the malicious payload to bypass security inspection. This vulnerability affects both local installations and integrated services like Hugging Face's online scanners. The issue is resolved in version 0.0.27.

Affected products

  • picklescan picklescan < 0.0.27
  • modelscan modelscan All versions prior to fix

Timeline

  • 2025-08-10: advisory: GitHub Security Advisory published
  • 2026-06-17: disclosed: NVD publication date

References

Related threats