Junglewise Threat Intelligence

CVE-2025-71348: picklescan detection bypass in torch.utils._config_module.load_config

CVE-2025-71348 · Severity: high · CVSS 8.1 · Published 2026-06-21

Technologies: Mmaitre314 Picklescan. Vendors: PyPI.

Executive brief

Picklescan is a Python library used to scan pickle files for potentially malicious code before loading them. This vulnerability allows attackers to embed arbitrary code in pickle files that evades Picklescan's detection by leveraging a PyTorch function (torch.utils._config_module.load_config) as a gadget. When a victim loads the pickle file, the embedded code executes, potentially enabling supply-chain attacks on machine learning models and other serialized Python objects.

Technical details

This vulnerability is a detection bypass in the Picklescan library (CWE-345: Insufficient Verification of Data Authenticity). The root cause is that Picklescan fails to recognize torch.utils._config_module.load_config as a dangerous function when called via the pickle __reduce__ method. An attacker crafts a pickle payload that calls load_config with a malicious nested pickle as an argument; when Picklescan scans this file, it does not flag it as dangerous, allowing the victim to call pickle.load() and trigger remote code execution. The attack requires no authentication or privileges, relies on network delivery of the pickle file, and requires user interaction (victim must check and then load the file). The vulnerability affects Picklescan versions ≤ 0.0.27 and is fixed in 0.0.28.

Affected products

  • mmaitre314 picklescan <= 0.0.27

Timeline

  • 2025-08-22: disclosed: Vulnerability published to GitHub Advisory Database
  • 2025-08-22: patched: Fix released in Picklescan 0.0.28

References

Related threats