Junglewise Threat Intelligence

CVE-2025-71360: picklescan detection bypass via idlelib.calltip.get_entity

CVE-2025-71360 · Severity: high · CVSS 8.1 · Published 2026-07-04

Technologies: Picklescan.

Executive brief

picklescan is a security tool used to scan Python pickle files and machine learning models for malicious code. A vulnerability in versions before 0.0.29 allows specially crafted malicious files to bypass detection by using a specific Python library function. If a user relies on the tool's "safe" verdict and subsequently opens the file, an attacker could execute arbitrary commands on their system, potentially leading to a full system compromise or data theft.

Technical details

A deserialization vulnerability (CWE-502) exists in picklescan due to an incomplete blocklist of dangerous functions. Specifically, the tool fails to identify the 'idlelib.calltip.get_entity' function when used within a pickle's '__reduce__' method. Because 'get_entity' internally performs an evaluation of its input, an attacker can craft a malicious pickle file that executes arbitrary Python code (e.g., os.system calls). The attack requires a victim to scan the file with an affected version of picklescan and, believing it to be safe, proceed to load it using 'pickle.load()'. This issue is resolved in version 0.0.29.

Affected products

  • picklescan picklescan < 0.0.29

Timeline

  • 2025-08-26: advisory: Initial GHSA advisory published
  • 2026-07-04: disclosed: CVE-2025-71360 published to NVD

References