Junglewise Threat Intelligence

CVE-2025-71345: picklescan detection bypass via torch.utils.bottleneck

CVE-2025-71345 · Severity: high · CVSS 8.1 · Published 2026-07-04

Technologies: Picklescan.

Executive brief

picklescan is a security tool used to scan Python "pickle" files for malicious code, commonly used to verify the safety of AI and Machine Learning models. A vulnerability was found where the tool fails to identify a specific dangerous function, allowing a malicious file to bypass security checks. If a user trusts the scan results and opens the file, an attacker could gain full control over the user's system.

Technical details

A deserialization vulnerability (CWE-502) exists in picklescan versions prior to 0.0.30. The tool's blocklist/allowlist mechanism fails to account for the 'torch.utils.bottleneck.__main__.run_autograd_prof' function, which can be leveraged to execute arbitrary Python code during the unpickling process. An attacker can craft a malicious pickle file that bypasses picklescan's detection; when a victim subsequently loads this file using 'pickle.load()', the embedded payload executes. This enables remote code execution (RCE) with the privileges of the application loading the model. The issue is resolved in version 0.0.30.

Affected products

  • picklescan picklescan < 0.0.30

Timeline

  • 2025-08-26: advisory: Initial GitHub security advisory published
  • 2026-07-03: disclosed: CVE-2025-71345 published to NVD

References