Junglewise Threat Intelligence

CVE-2025-71367: picklescan security bypass via _operator.attrgetter function call

CVE-2025-71367 · Severity: high · CVSS 8.1 · Published 2026-07-04

Technologies: Picklescan.

Executive brief

picklescan is a security tool used to scan Python pickle files and machine learning models for malicious code. A flaw in the tool allows specially crafted files to bypass its security checks by using a specific Python function. If a user relies on picklescan to verify a file and then opens it, an attacker could execute arbitrary commands on the user's system.

Technical details

A deserialization vulnerability (CWE-502) exists in picklescan due to an incomplete denylist of dangerous functions. Specifically, the tool fails to identify and flag the '_operator.attrgetter' function when used within a pickle's reduce method. An attacker can craft a malicious pickle file that uses this function to trigger arbitrary code execution upon loading. While picklescan is intended to prevent such attacks by pre-scanning files, this bypass allows malicious payloads to be marked as safe. The issue is resolved in version 0.0.34.

Affected products

  • picklescan picklescan < 0.0.34

Timeline

  • 2025-12-27: advisory: GitHub Security Advisory published
  • 2026-07-04: disclosed: NVD publication date

References