Executive brief
Picklescan is a security tool used to scan Python pickle files and AI models for malicious code. A flaw in how the tool parses specific data structures allows attackers to craft malicious files that bypass security checks entirely. This could lead to the execution of unauthorized code on systems that rely on these scans to verify the safety of uploaded models or data.
Technical details
A logic error exists in the _list_globals function of picklescan (and by extension modelscan) when processing the STACK_GLOBAL opcode. The function fails to include the zero-index position when tracking stack arguments, causing it to miscount the number of arguments present. By placing a malicious argument at position zero, an attacker can trigger an 'Unchecked Error Condition' (CWE-391) that results in an unexpected exception. This exception halts the scanning process prematurely, allowing the malicious pickle file to be treated as safe or otherwise bypass the security filter. The vulnerability is resolved in version 0.0.27.
Affected products
- mmaitre314 picklescan < 0.0.27
- protectai modelscan < 0.0.27
Timeline
- 2025-08-10: advisory: Original GHSA-9gvj-pp9x-gcfr published
- 2026-06-17: disclosed: CVE-2025-71325 assigned
- 2026-06-18: other: Duplicate advisory GHSA-5rph-q42j-36j9 withdrawn