Junglewise Threat Intelligence

CVE-2026-53875: picklescan scanning bypass in scan_pytorch

CVE-2026-53875 · Severity: high · CVSS 4 · Published 2026-06-17

Technologies: Picklescan. Vendors: PyPI.

Executive brief

picklescan is a security tool used to scan Python machine learning models for malicious code. A vulnerability in its PyTorch scanning component allows attackers to hide malicious commands within a model file in a way that bypasses the scanner's detection. If a user trusts the scanner's clean report and loads the malicious model, an attacker can execute arbitrary code on the user's system.

Technical details

A scanning bypass exists in the `scan_pytorch` function of picklescan due to an implementation discrepancy in how magic numbers are retrieved compared to PyTorch's `pickle_module.load()`. While picklescan uses `pickletools.genops()` to identify magic numbers (expecting INT or LONG types), an attacker can use the `__reduce__` magic method and `eval()` to dynamically generate the magic number. This causes picklescan to fail to identify the magic number and skip deep inspection, while the payload remains valid and executable when loaded via `torch.load()`. Successful exploitation allows for arbitrary code execution (ACE) when a victim loads a specially crafted PyTorch model that was previously flagged as safe by picklescan. The issue is fixed in version 1.0.3.

Affected products

  • picklescan picklescan < 1.0.3

Timeline

  • 2026-02-16: advisory: GitHub Security Advisory published
  • 2026-06-17: disclosed: NVD publication date

References

Related threats