Executive brief
Picklescan is a security library used to scan Python pickle files for malicious code before loading them. A flaw in its detection mechanism allows attackers to embed arbitrary code using NumPy's internal eval function, which picklescan fails to recognize as dangerous. When a user loads such a crafted pickle file after clearing it with picklescan, the malicious code executes, potentially compromising systems handling Python machine learning models or serialized objects.
Technical details
This is a deserialization vulnerability (CWE-502) in picklescan's malicious code detection engine. The vulnerability occurs because picklescan does not detect when the pickle reduce method calls numpy.f2py.crackfortran.myeval, a NumPy function that can evaluate arbitrary code. An attacker crafts a pickle file containing a class with a __reduce__ method that returns a callable to myeval with Python code as a string argument. Picklescan inspects the file and fails to flag this as dangerous because it lacks detection rules for this specific NumPy function. When the victim calls pickle.load() on the file after passing it through picklescan, the myeval function executes the embedded code with the user's privileges. The attack vector is network-based with user interaction required (the victim must both run picklescan and then load the pickle file). The issue was patched in picklescan version 0.0.33.
Affected products
- picklescan picklescan < 0.0.33
Timeline
- 2025-12-27: disclosed: Original advisory GHSA-3329-ghmp-jmv5 published
- 2026-06-23: disclosed: Duplicate advisory GHSA-x36p-c636-788x published
- 2026-09-23: advisory: Duplicate advisory GHSA-x36p-c636-788x withdrawn
- 2026-06-23: patched: Version 0.0.33 includes patch