Junglewise Threat Intelligence

CVE-2025-71353: picklescan detection bypass via torch._dynamo.guards.GuardBuilder.get

CVE-2025-71353 · Severity: high · CVSS 8.1 · Published 2026-07-04

Technologies: Picklescan.

Executive brief

Picklescan is a security tool used to scan Python pickle files and machine learning models for malicious code. A vulnerability in versions before 0.0.28 allows specially crafted files to bypass security checks by using a specific PyTorch function. If a user trusts the scan results and opens the file, an attacker could gain full control over the system, potentially leading to data theft or a complete system compromise.

Technical details

A deserialization vulnerability (CWE-502) exists in picklescan due to an incomplete blocklist or detection logic. Specifically, the tool fails to identify the 'torch._dynamo.guards.GuardBuilder.get' function when used within a pickle 'reduce' method. An attacker can craft a malicious pickle file that leverages this function to execute arbitrary Python code (e.g., os.system calls). Because picklescan reports the file as safe, a victim is more likely to proceed with 'pickle.load()', resulting in arbitrary command execution. The issue is resolved in version 0.0.28.

Affected products

  • picklescan picklescan < 0.0.28

Timeline

  • 2025-08-22: advisory: Initial GitHub Security Advisory published
  • 2026-07-04: disclosed: NVD publication and CVE assignment
  • 2025-08-22: patched: Version 0.0.28 released to address the bypass

References