Executive brief
Picklescan is a security tool used to scan Python pickle files and machine learning models for malicious code. A vulnerability in versions before 0.0.28 allows specially crafted files to bypass security checks by using a specific PyTorch function. If a user trusts the scan results and opens the file, an attacker could gain full control over the system, potentially leading to data theft or a complete system compromise.
Technical details
A deserialization vulnerability (CWE-502) exists in picklescan due to an incomplete blocklist or detection logic. Specifically, the tool fails to identify the 'torch._dynamo.guards.GuardBuilder.get' function when used within a pickle 'reduce' method. An attacker can craft a malicious pickle file that leverages this function to execute arbitrary Python code (e.g., os.system calls). Because picklescan reports the file as safe, a victim is more likely to proceed with 'pickle.load()', resulting in arbitrary command execution. The issue is resolved in version 0.0.28.
Affected products
- picklescan picklescan < 0.0.28
Timeline
- 2025-08-22: advisory: Initial GitHub Security Advisory published
- 2026-07-04: disclosed: NVD publication and CVE assignment
- 2025-08-22: patched: Version 0.0.28 released to address the bypass