Executive brief
picklescan is a security tool used to scan Python pickle files and machine learning models for malicious code. A vulnerability in versions before 0.0.33 allows specially crafted malicious files to bypass detection by using a specific NumPy function. If a user relies on the tool to verify a file and then opens it, an attacker could gain full control over the system running the code.
Technical details
A security bypass exists in picklescan versions prior to 0.0.33 due to an incomplete blocklist of dangerous functions. Specifically, the tool fails to identify the 'numpy.f2py.crackfortran.param_eval' function when used within a pickle's __reduce__ method. An attacker can craft a malicious pickle file that executes arbitrary Python code (e.g., via os.system) during deserialization. Because picklescan reports the file as safe, users are likely to proceed with loading the untrusted data using pickle.load(), resulting in remote code execution. The issue is addressed in version 0.0.33.
Affected products
- picklescan picklescan < 0.0.33
Timeline
- 2025-12-27: advisory: GitHub Security Advisory published
- 2026-07-04: disclosed: NVD publication date