Junglewise Threat Intelligence

Picklescan remote code execution via incomplete deny-list

Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: picklescan (PyPI). Vendors: PyPI.

Executive brief

Picklescan is a security tool used to scan Python pickle files for malicious code. A vulnerability in its detection logic allows specially crafted files to bypass security checks by using unblocked functions. If an attacker successfully bypasses these checks, they can execute arbitrary commands on the system scanning the file, potentially leading to a full system compromise.

Technical details

Picklescan before version 0.0.33 contains an incomplete deny-list (CWE-184) that fails to block the 'pydoc.locate' and 'operator.methodcaller' functions. An attacker can leverage 'pydoc.locate' to dynamically resolve modules and 'operator.methodcaller' to execute methods like 'os.system' within a pickle file. Because these functions were not explicitly flagged as dangerous, the tool treats them as safe or suspicious rather than blocking them. This allows a remote attacker to achieve arbitrary code execution (RCE) when the malicious pickle file is deserialized by a user or system relying on Picklescan for validation. The issue is resolved in version 0.0.33 by implementing a wildcard block on the affected modules.

Affected products

  • mmaitre314 picklescan < 0.0.33

Timeline

  • 2025-12-26: advisory: Original GHSA-84r2-jw7c-4r5q published by maintainer
  • 2026-06-17: disclosed: CVE-2025-71320 published to NVD
  • 2026-06-18: other: Duplicate advisory GHSA-6v84-v468-3c7f withdrawn

References

Related threats