Junglewise Threat Intelligence

CVE-2026-53874: picklescan unsafe deserialization via obfuscated eval call

CVE-2026-53874 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: picklescan (PyPI). Vendors: PyPI.

Executive brief

picklescan is a security tool designed to detect malicious code within Python pickle files, which are commonly used to store machine learning models and data. A vulnerability in the tool allows attackers to bypass its security checks by obfuscating malicious commands, leading to the execution of unauthorized code on the system running the scan. This could allow an attacker to take full control of a server or workstation that is processing untrusted files.

Technical details

An unsafe deserialization vulnerability (CWE-502) exists in picklescan versions prior to 1.0.1. The tool fails to detect malicious 'eval' calls when they are nested under other callable objects using 'getattr' obfuscation. An attacker can craft a malicious pickle file that evades the scanner's detection logic but executes arbitrary Python code when the file is subsequently loaded by a victim. This bypass is achieved by using the '__reduce__' method to trigger an obfuscated call to 'builtins.eval'. The issue is resolved in version 1.0.1.

Affected products

  • picklescan picklescan < 1.0.1

Timeline

  • 2026-02-02: advisory: GitHub Security Advisory published
  • 2026-06-17: disclosed: NVD publication date

References

Related threats