Junglewise Threat Intelligence

CVE-2025-71340: picklescan detection bypass in idlelib.pyshell.ModifiedInterpreter.runcode

CVE-2025-71340 · Severity: high · CVSS 8.1 · Published 2026-06-25

Technologies: Picklescan.

Executive brief

picklescan is a security tool used to scan Python "pickle" files and AI models (like PyTorch) for malicious code. A flaw in the tool allows specially crafted malicious files to bypass detection by using an obscure built-in Python function. If a user trusts the scan results and opens the file, an attacker could gain full control over the system, potentially leading to data theft or a supply chain compromise.

Technical details

A deserialization vulnerability exists in picklescan versions up to 0.0.26 due to an incomplete blocklist of dangerous functions. Specifically, the tool fails to identify the use of 'idlelib.pyshell.ModifiedInterpreter.runcode' within a pickle file's '__reduce__' method. An attacker can craft a malicious pickle file or PyTorch model that, when scanned, appears safe but executes arbitrary Python code upon being loaded via 'pickle.load()'. This bypass enables remote code execution (RCE) and supply chain attacks. The issue is resolved in version 0.0.30.

Affected products

  • picklescan picklescan <= 0.0.26

Timeline

  • 2025-08-26: advisory: Initial GitHub security advisory published
  • 2026-06-25: disclosed: NVD publication date

References