Executive brief
Picklescan is a security tool used to scan machine learning models for malicious code before they are loaded. A vulnerability in how it checks PyTorch files allows attackers to hide malicious code inside a model file in a way that bypasses the scanner's detection. If a user is tricked into loading one of these "clean-looking" but malicious files, an attacker could execute arbitrary commands on the user's computer.
Technical details
A scanning bypass exists in picklescan's 'scan_pytorch' function due to a discrepancy between how the scanner and PyTorch identify file magic numbers. While picklescan uses 'pickletools.genops' to look for specific integer or long opcodes, PyTorch uses 'pickle_module.load()'. An attacker can use the '__reduce__' magic method and 'eval' to dynamically generate the expected magic number at runtime. This allows a malicious PyTorch payload to appear invalid or benign to the scanner while remaining fully executable by 'torch.load()', leading to arbitrary code execution. The issue is addressed in version 1.0.3.
Affected products
- mmaitre314 picklescan < 1.0.3
Timeline
- 2026-02-16: advisory: Original GHSA-97f8-7cmv-76j2 published
- 2026-06-17: disclosed: CVE-2026-53875 published
- 2026-06-18: other: Duplicate advisory GHSA-cc5p-54x3-hcf8 withdrawn
References
- https://github.com/mmaitre314/picklescan/security/advisories/GHSA-97f8-7cmv-76j2
- https://github.com/mmaitre314/picklescan/commit/134179474539648ba7dee1317959529fbd0e7f89
- https://github.com/mmaitre314/picklescan/commit/2a8383cfeb4158567f9770d86597300c9e508d0f
- https://www.vulncheck.com/advisories/picklescan-scanning-bypass-via-dynamic-eval-in-scan-pytorch