Junglewise Threat Intelligence

CVE-2025-71342: picklescan detection bypass via idlelib.run.Executive.runcode

CVE-2025-71342 · Severity: high · CVSS 8.1 · Published 2026-07-04

Technologies: Picklescan.

Executive brief

picklescan is a security tool used to scan Python pickle files and machine learning models for malicious code. A vulnerability in versions before 0.0.30 allows specially crafted malicious files to bypass detection by using a specific built-in Python function. If a user trusts the scan results and opens the file, an attacker could gain full control over the user's system, potentially leading to data theft or supply chain attacks.

Technical details

A deserialization vulnerability exists in picklescan due to an incomplete blocklist of dangerous functions. Specifically, the scanner fails to identify the use of 'idlelib.run.Executive.runcode' within a pickle object's '__reduce__' method. An attacker can craft a malicious pickle file or PyTorch model that, when scanned, appears benign but executes arbitrary Python code upon being loaded with 'pickle.load()'. This bypasses the primary security guarantee of the library. The issue is addressed in version 0.0.30.

Affected products

  • picklescan picklescan < 0.0.30

Timeline

  • 2025-08-26: advisory: GitHub Security Advisory published
  • 2026-07-04: disclosed: NVD publication date
  • 2025-08-26: patched: Version 0.0.30 released

References