Executive brief
Picklescan is a security scanner used to detect malicious code in pickle files—serialized Python objects commonly found in machine learning models. The tool has a critical gap: it fails to detect exploits that abuse Python's timeit.timeit() function, allowing attackers to craft seemingly safe pickle files that execute arbitrary system commands when loaded. This creates a supply-chain risk for organizations distributing or consuming ML models, as infected files bypass security scanning and remain hidden until execution.
Technical details
Picklescan maintains a blacklist of unsafe functions that can be called during pickle deserialization to prevent arbitrary code execution. However, the timeit library (a built-in Python timing utility) was not included in this blacklist. Attackers exploit this gap by crafting pickle payloads that call timeit.timeit() from the __reduce__ method; inside timeit's execution context, arbitrary code (such as os.system() calls) runs without detection. The vulnerability requires the victim to deserialize a malicious pickle file using pickle.load() after Picklescan clears it. The attack vector is network-based (malicious pickle files can be distributed remotely), though user interaction is passive—the victim simply loads a file they believe is safe. Fixed in version 0.0.25 by adding timeit to the unsafe globals blacklist.
Affected products
- Picklescan picklescan < 0.0.25
Timeline
- 2026-04-06: disclosed: Original advisory GHSA-v7x6-rv5q-mhwc published
- 2026-06-21: disclosed: Duplicate advisory GHSA-fh2f-24rh-r2vq published and indexed in NVD
- 2026-06-21: patched: Fix available in picklescan version 0.0.25
- 2026-09-11: other: Duplicate advisory GHSA-fh2f-24rh-r2vq withdrawn; original GHSA-v7x6-rv5q-mhwc remains active