Executive brief
picklescan is a security tool used to scan Python machine learning models for malicious code. A vulnerability in its PyTorch scanning component allows attackers to hide malicious commands within a model file in a way that bypasses the scanner's detection. If a user trusts the scanner's clean report and loads the malicious model, an attacker can execute arbitrary code on the user's system.
Technical details
A scanning bypass exists in the `scan_pytorch` function of picklescan due to an implementation discrepancy in how magic numbers are retrieved compared to PyTorch's `pickle_module.load()`. While picklescan uses `pickletools.genops()` to identify magic numbers (expecting INT or LONG types), an attacker can use the `__reduce__` magic method and `eval()` to dynamically generate the magic number. This causes picklescan to fail to identify the magic number and skip deep inspection, while the payload remains valid and executable when loaded via `torch.load()`. Successful exploitation allows for arbitrary code execution (ACE) when a victim loads a specially crafted PyTorch model that was previously flagged as safe by picklescan. The issue is fixed in version 1.0.3.
Affected products
- picklescan picklescan < 1.0.3
Timeline
- 2026-02-16: advisory: GitHub Security Advisory published
- 2026-06-17: disclosed: NVD publication date
References
- https://github.com/mmaitre314/picklescan/commit/134179474539648ba7dee1317959529fbd0e7f89
- https://github.com/mmaitre314/picklescan/commit/2a8383cfeb4158567f9770d86597300c9e508d0f
- https://github.com/mmaitre314/picklescan/security/advisories/GHSA-97f8-7cmv-76j2
- https://www.vulncheck.com/advisories/picklescan-scanning-bypass-via-dynamic-eval-in-scan-pytorch