Junglewise Threat Intelligence

CVE-2025-71355: Picklescan detection bypass via unsafe Numpy functions

CVE-2025-71355 · Severity: medium · CVSS 4 · Published 2026-06-30

Technologies: Mmaitre314 Picklescan.

Executive brief

Picklescan is a security tool used to scan Python pickle files and machine learning models for malicious code. A vulnerability was discovered where the tool fails to identify dangerous functions within the Numpy library, allowing specially crafted malicious files to bypass security checks. If a user trusts the scan results and opens such a file, an attacker could execute arbitrary commands on the user's system, potentially leading to a full system compromise.

Technical details

Picklescan (versions prior to 0.0.25) contains an incomplete list of disallowed inputs (CWE-184) in its safety blacklist. Specifically, it fails to flag the 'numpy.testing._private.utils.runstring' function, which can be used within a pickle's __reduce__ method to execute arbitrary Python code. An attacker can craft a malicious pickle file that imports the 'os' library via this Numpy function to execute shell commands. The vulnerability is exploited when a victim scans a malicious file, receives a 'clean' report due to the bypass, and subsequently loads the file using 'pickle.load()'. The issue is resolved in version 0.0.25 by adding Numpy to the unsafe globals list.

Affected products

  • mmaitre314 picklescan < 0.0.25

Timeline

  • 2025-04-06: advisory: GitHub Security Advisory published
  • 2026-06-30: disclosed: NVD publication date

References