Junglewise Threat Intelligence

CVE-2025-71352: picklescan detection bypass via trace.Trace.runctx

CVE-2025-71352 · Severity: high · CVSS 8.1 · Published 2026-06-30

Technologies: Picklescan.

Executive brief

picklescan is a security tool used to scan Python pickle files and machine learning models for malicious code. A vulnerability in this tool allows specially crafted malicious files to bypass detection by using a specific Python function (trace.Trace.runctx). If a user relies on picklescan to verify a file and then opens it, an attacker could gain full control over the user's system and execute arbitrary commands.

Technical details

A protection mechanism failure exists in picklescan versions prior to 0.0.29. The scanner fails to identify the 'trace.Trace.runctx' function when embedded within a pickle file's '__reduce__' method. An attacker can exploit this by crafting a malicious pickle file (often distributed as a PyTorch model) that bypasses the scanner's blocklist. When a victim subsequently loads the file using 'pickle.load()', the payload executes arbitrary Python code with the privileges of the running process. The issue is resolved in version 0.0.29.

Affected products

  • picklescan picklescan < 0.0.29

Timeline

  • 2025-08-26: advisory: Initial GitHub security advisory published
  • 2026-06-30: disclosed: CVE published to NVD

References