Executive brief
Picklescan is a security tool used to scan Python pickle files and AI models for malicious code before they are opened. A vulnerability in this tool allows specially crafted malicious files to bypass its safety checks by using a specific hidden command. If a user relies on Picklescan to vet a file and then opens it, an attacker could gain full control over the user's system, potentially leading to data theft or supply-chain attacks.
Technical details
Picklescan is vulnerable to a deserialization bypass (CWE-502) because its blocklist/heuristic engine fails to identify the 'numpy.f2py.crackfortran.getlincoef' function as a dangerous gadget. An attacker can craft a malicious pickle file that utilizes this function within a '__reduce__' method to execute arbitrary Python code. When a victim scans the file, Picklescan incorrectly flags it as safe; subsequent loading of the file via 'pickle.load()' triggers the exploit. This vulnerability requires the victim to attempt to load the malicious file (User Interaction) and is resolved in version 0.0.33.
Affected products
- Picklescan Picklescan before 0.0.33
Timeline
- 2025-12-27: advisory: GitHub Security Advisory published
- 2026-07-03: disclosed: NVD publication date
- 2026-07-03: patched: Version 0.0.33 released