Executive brief
Picklescan is a security tool that scans pickle files (Python's serialization format) for malicious code before loading them. A vulnerability allows attackers to craft specially crafted pickle files that bypass Picklescan's detection by using PyTorch's torch.utils._config_module.load_config function, then execute arbitrary code when the file is loaded. This poses a significant supply chain risk for organizations using machine learning models or other Python serialized objects from untrusted sources.
Technical details
This vulnerability is a deserialization bypass (CWE-502) affecting Picklescan's detection engine. Attackers exploit a missing check for the torch.utils._config_module.load_config function in reduce methods—a specific mechanism for object reconstruction during pickle deserialization. The attack works by embedding a payload that calls ConfigModule.load_config with a malicious pickled object as an argument; the detector misses this code path and clears the file as safe, but pickle.load() executes the payload when deserializing. The attack requires user interaction (the victim must call pickle.load() after checking with Picklescan) and network delivery of the malicious pickle file. Patch version 0.0.28 addresses this by adding detection for this specific function call pattern.
Affected products
- mmaitre314 picklescan <= 0.0.27
Timeline
- 2026-06-21: disclosed: Published to GitHub Advisory Database
- 0.0.28: patched: Fix available in version 0.0.28
- 2026-09-11: other: Advisory withdrawn as duplicate of GHSA-vv6j-3g6g-2pvj