Executive brief
Picklescan is a security tool used to scan Python pickle files and machine learning models for malicious code. A vulnerability was discovered where the tool fails to identify dangerous functions within the Numpy library, allowing specially crafted malicious files to bypass security checks. If a user trusts the scan results and opens such a file, an attacker could execute arbitrary commands on the user's system, potentially leading to a full system compromise.
Technical details
Picklescan (versions prior to 0.0.25) contains an incomplete list of disallowed inputs (CWE-184) in its safety blacklist. Specifically, it fails to flag the 'numpy.testing._private.utils.runstring' function, which can be used within a pickle's __reduce__ method to execute arbitrary Python code. An attacker can craft a malicious pickle file that imports the 'os' library via this Numpy function to execute shell commands. The vulnerability is exploited when a victim scans a malicious file, receives a 'clean' report due to the bypass, and subsequently loads the file using 'pickle.load()'. The issue is resolved in version 0.0.25 by adding Numpy to the unsafe globals list.
Affected products
- mmaitre314 picklescan < 0.0.25
Timeline
- 2025-04-06: advisory: GitHub Security Advisory published
- 2026-06-30: disclosed: NVD publication date