Executive brief
Picklescan is a security tool used to detect malicious code hidden within Python pickle files, which are commonly used to store machine learning models. A vulnerability was found where the tool fails to detect a specific type of malicious code that uses a built-in Python library function. If an attacker successfully bypasses this scan, they could execute unauthorized commands on a victim's system when the malicious model is loaded, potentially leading to a full system compromise or data theft.
Technical details
Picklescan versions prior to 0.0.29 contain a detection bypass vulnerability. The tool fails to flag the use of 'idlelib.calltip.Calltip.fetch_tip' within a pickle file's __reduce__ method. This specific function eventually calls 'eval()' on its input. An attacker can craft a malicious pickle file that, when scanned by Picklescan, appears safe but executes arbitrary Python code (e.g., via os.system) when deserialized using 'pickle.load()'. This bypass is particularly relevant for supply chain attacks involving PyTorch models or other serialized Python objects. The issue is fixed in version 0.0.29.
Affected products
- mmaitre314 picklescan < 0.0.29
Timeline
- 2025-08-26: advisory: GitHub Advisory published
- 2025-08-26: patched: Fix released in version 0.0.29