Executive brief
picklescan is a security tool used to scan Python pickle files and machine learning models for malicious code. A vulnerability in this tool allows specially crafted malicious files to bypass detection by using a specific Python function (trace.Trace.runctx). If a user relies on picklescan to verify a file and then opens it, an attacker could gain full control over the user's system and execute arbitrary commands.
Technical details
A protection mechanism failure exists in picklescan versions prior to 0.0.29. The scanner fails to identify the 'trace.Trace.runctx' function when embedded within a pickle file's '__reduce__' method. An attacker can exploit this by crafting a malicious pickle file (often distributed as a PyTorch model) that bypasses the scanner's blocklist. When a victim subsequently loads the file using 'pickle.load()', the payload executes arbitrary Python code with the privileges of the running process. The issue is resolved in version 0.0.29.
Affected products
- picklescan picklescan < 0.0.29
Timeline
- 2025-08-26: advisory: Initial GitHub security advisory published
- 2026-06-30: disclosed: CVE published to NVD