{"schema_version":1,"title":"picklescan (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 78 vulnerabilities in picklescan (PyPI): 0 in the last 7 days and 24 in the last 90 days, 16 of them critical and 0 exploited in the wild. The most recent, CVE-2025-71375, was published on 4 July 2026.","url":"https://junglewise.ai/threats/technologies/picklescan","json_url":"https://junglewise.ai/threats/technologies/picklescan.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/picklescan","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":53,"all_time":78,"critical":16,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":24,"last_365_days":70},"latest":[{"cve":"CVE-2025-71375","cvss":8.1,"epss":0.0052,"slug":"cve-2025-71375-picklescan-detection-bypass-via-operator-methodcaller","title":"picklescan detection bypass via _operator.methodcaller","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:23.347+00:00","url":"https://junglewise.ai/threats/cve-2025-71375-picklescan-detection-bypass-via-operator-methodcaller"},{"cve":"CVE-2025-71373","cvss":8.1,"epss":0.0064,"slug":"cve-2025-71373-picklescan-security-bypass-via-operator-methodcaller","title":"picklescan security bypass via operator.methodcaller","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:23.22+00:00","url":"https://junglewise.ai/threats/cve-2025-71373-picklescan-security-bypass-via-operator-methodcaller"},{"cve":"CVE-2025-71372","cvss":8.1,"epss":0.0054,"slug":"cve-2025-71372-picklescan-detection-bypass-via-numpy-getlincoef-gadget","title":"Picklescan detection bypass via numpy getlincoef gadget","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:23.097+00:00","url":"https://junglewise.ai/threats/cve-2025-71372-picklescan-detection-bypass-via-numpy-getlincoef-gadget"},{"cve":"CVE-2025-71369","cvss":8.1,"epss":0.0064,"slug":"cve-2025-71369-picklescan-safety-check-bypass-via-pytorch-decoder-basichandlers","title":"picklescan safety check bypass via PyTorch decoder basichandlers","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:22.963+00:00","url":"https://junglewise.ai/threats/cve-2025-71369-picklescan-safety-check-bypass-via-pytorch-decoder-basichandlers"},{"cve":"CVE-2025-71367","cvss":8.1,"epss":0.0064,"slug":"cve-2025-71367-picklescan-security-bypass-via-operator-attrgetter-function-call","title":"picklescan security bypass via _operator.attrgetter function call","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:22.833+00:00","url":"https://junglewise.ai/threats/cve-2025-71367-picklescan-security-bypass-via-operator-attrgetter-function-call"},{"cve":"CVE-2025-71366","cvss":8.1,"epss":0.0064,"slug":"cve-2025-71366-picklescan-security-bypass-via-torch-utils-bottleneck-in-pickle","title":"picklescan security bypass via torch.utils.bottleneck in pickle files","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:22.707+00:00","url":"https://junglewise.ai/threats/cve-2025-71366-picklescan-security-bypass-via-torch-utils-bottleneck-in-pickle"},{"cve":"CVE-2025-71364","cvss":8.1,"epss":0.0083,"slug":"cve-2025-71364-picklescan-detection-bypass-in-asyncio-unix-events","title":"picklescan detection bypass in asyncio unix_events","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:22.583+00:00","url":"https://junglewise.ai/threats/cve-2025-71364-picklescan-detection-bypass-in-asyncio-unix-events"},{"cve":"CVE-2025-71362","cvss":8.1,"epss":0.0043,"slug":"cve-2025-71362-picklescan-detection-bypass-in-numpy-f2py-crackfortran","title":"picklescan detection bypass in numpy.f2py.crackfortran","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:22.457+00:00","url":"https://junglewise.ai/threats/cve-2025-71362-picklescan-detection-bypass-in-numpy-f2py-crackfortran"},{"cve":"CVE-2025-71360","cvss":8.1,"epss":0.0043,"slug":"cve-2025-71360-picklescan-detection-bypass-via-idlelib-calltip-get-entity","title":"picklescan detection bypass via idlelib.calltip.get_entity","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:22.327+00:00","url":"https://junglewise.ai/threats/cve-2025-71360-picklescan-detection-bypass-via-idlelib-calltip-get-entity"},{"cve":"CVE-2025-71359","cvss":8.1,"epss":0.0061,"slug":"cve-2025-71359-picklescan-detection-bypass-via-lib2to3-grammar-loads","title":"picklescan detection bypass via lib2to3 Grammar.loads","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:22.197+00:00","url":"https://junglewise.ai/threats/cve-2025-71359-picklescan-detection-bypass-via-lib2to3-grammar-loads"},{"cve":"CVE-2025-71356","cvss":8.1,"epss":0.0043,"slug":"cve-2025-71356-picklescan-detection-bypass-in-torch-fx-experimental-symbolic","title":"picklescan detection bypass in torch.fx.experimental.symbolic_shapes","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:22.063+00:00","url":"https://junglewise.ai/threats/cve-2025-71356-picklescan-detection-bypass-in-torch-fx-experimental-symbolic"},{"cve":"CVE-2025-71353","cvss":8.1,"epss":0.0043,"slug":"cve-2025-71353-picklescan-detection-bypass-via-torch-dynamo-guards-guardbuilder","title":"picklescan detection bypass via torch._dynamo.guards.GuardBuilder.get","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:21.933+00:00","url":"https://junglewise.ai/threats/cve-2025-71353-picklescan-detection-bypass-via-torch-dynamo-guards-guardbuilder"},{"cve":"CVE-2025-71347","cvss":8.1,"epss":0.0064,"slug":"cve-2025-71347-picklescan-security-bypass-via-numpy-f2py-crackfortran-param-eval","title":"picklescan security bypass via numpy.f2py.crackfortran.param_eval","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:21.803+00:00","url":"https://junglewise.ai/threats/cve-2025-71347-picklescan-security-bypass-via-numpy-f2py-crackfortran-param-eval"},{"cve":"CVE-2025-71345","cvss":8.1,"epss":0.0061,"slug":"cve-2025-71345-picklescan-detection-bypass-via-torch-utils-bottleneck","title":"picklescan detection bypass via torch.utils.bottleneck","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:21.67+00:00","url":"https://junglewise.ai/threats/cve-2025-71345-picklescan-detection-bypass-via-torch-utils-bottleneck"},{"cve":"CVE-2025-71343","cvss":8.1,"epss":0.0043,"slug":"cve-2025-71343-picklescan-detection-bypass-via-lib2to3-parsergenerator","title":"picklescan detection bypass via lib2to3 ParserGenerator","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:21.527+00:00","url":"https://junglewise.ai/threats/cve-2025-71343-picklescan-detection-bypass-via-lib2to3-parsergenerator"},{"cve":"CVE-2025-71342","cvss":8.1,"epss":0.0061,"slug":"cve-2025-71342-picklescan-detection-bypass-via-idlelib-run-executive-runcode","title":"picklescan detection bypass via idlelib.run.Executive.runcode","severity":"high","exploited":false,"published_at":"2026-07-04T02:16:21.387+00:00","url":"https://junglewise.ai/threats/cve-2025-71342-picklescan-detection-bypass-via-idlelib-run-executive-runcode"},{"cve":"CVE-2025-71374","cvss":8.1,"epss":0.0064,"slug":"cve-2025-71374-picklescan-detection-bypass-via-profile-profile-run","title":"picklescan detection bypass via profile.Profile.run","severity":"high","exploited":false,"published_at":"2026-06-30T23:16:51.903+00:00","url":"https://junglewise.ai/threats/cve-2025-71374-picklescan-detection-bypass-via-profile-profile-run"},{"cve":"CVE-2025-71371","cvss":8.1,"epss":0.0054,"slug":"cve-2025-71371-picklescan-detection-bypass-via-code-interactiveinterpreter","title":"picklescan detection bypass via code.InteractiveInterpreter.runcode","severity":"high","exploited":false,"published_at":"2026-06-30T23:16:51.773+00:00","url":"https://junglewise.ai/threats/cve-2025-71371-picklescan-detection-bypass-via-code-interactiveinterpreter"},{"cve":"CVE-2025-71368","cvss":8.1,"epss":0.0084,"slug":"cve-2025-71368-picklescan-detection-bypass-via-doctest-debug-script","title":"picklescan detection bypass via doctest.debug_script","severity":"high","exploited":false,"published_at":"2026-06-30T23:16:51.653+00:00","url":"https://junglewise.ai/threats/cve-2025-71368-picklescan-detection-bypass-via-doctest-debug-script"},{"cve":"CVE-2025-71363","cvss":8.1,"epss":0.0064,"slug":"cve-2025-71363-picklescan-code-execution-bypass-via-cprofile-run-in-pickle","title":"picklescan code execution bypass via cProfile.run in pickle reduce","severity":"high","exploited":false,"published_at":"2026-06-30T23:16:51.533+00:00","url":"https://junglewise.ai/threats/cve-2025-71363-picklescan-code-execution-bypass-via-cprofile-run-in-pickle"},{"cve":"CVE-2025-71355","cvss":4,"epss":0.0058,"slug":"cve-2025-71355-picklescan-detection-bypass-via-unsafe-numpy-functions","title":"Picklescan detection bypass via unsafe Numpy functions","severity":"medium","exploited":false,"published_at":"2026-06-30T23:16:51.417+00:00","url":"https://junglewise.ai/threats/cve-2025-71355-picklescan-detection-bypass-via-unsafe-numpy-functions"},{"cve":"CVE-2025-71352","cvss":8.1,"epss":0.0064,"slug":"cve-2025-71352-picklescan-detection-bypass-via-trace-trace-runctx","title":"picklescan detection bypass via trace.Trace.runctx","severity":"high","exploited":false,"published_at":"2026-06-30T23:16:51.29+00:00","url":"https://junglewise.ai/threats/cve-2025-71352-picklescan-detection-bypass-via-trace-trace-runctx"},{"cve":"CVE-2025-71350","cvss":8.1,"epss":0.0043,"slug":"cve-2025-71350-picklescan-detection-bypass-via-torch-utils-collect-env-run","title":"picklescan detection bypass via torch.utils.collect_env.run","severity":"high","exploited":false,"published_at":"2026-06-30T23:16:51.163+00:00","url":"https://junglewise.ai/threats/cve-2025-71350-picklescan-detection-bypass-via-torch-utils-collect-env-run"},{"cve":"CVE-2025-71349","cvss":8.1,"epss":0.0061,"slug":"cve-2025-71349-picklescan-detection-bypass-via-trace-trace-run-function","title":"picklescan detection bypass via trace.Trace.run function","severity":"high","exploited":false,"published_at":"2026-06-30T23:16:51.01+00:00","url":"https://junglewise.ai/threats/cve-2025-71349-picklescan-detection-bypass-via-trace-trace-run-function"},{"cve":"CVE-2025-71340","cvss":8.1,"epss":0.0043,"slug":"cve-2025-71340-picklescan-detection-bypass-in-idlelib-pyshell","title":"picklescan detection bypass in idlelib.pyshell.ModifiedInterpreter.runcode","severity":"high","exploited":false,"published_at":"2026-06-25T22:16:59.647+00:00","url":"https://junglewise.ai/threats/cve-2025-71340-picklescan-detection-bypass-in-idlelib-pyshell"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":24},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"},{"name":"opencv-contrib-python (PyPI)","slug":"opencv-contrib-python","vulnerabilities":24,"url":"https://junglewise.ai/threats/technologies/opencv-contrib-python"}],"technology":{"hub":true,"name":"picklescan (PyPI)","slug":"picklescan","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://pypi.org/project/picklescan/","repo_url":"https://github.com/checkpoint-sw/picklescan","description":"A security tool for scanning Python pickle files for malicious code.","url":"https://junglewise.ai/threats/technologies/picklescan"},"most_severe":[{"cve":"CVE-2026-3490","cvss":10,"epss":0.0091,"slug":"cve-2026-3490-picklescan-blocklist-bypass-via-pkgutil-resolve-name","title":"picklescan blocklist bypass via pkgutil.resolve_name","severity":"critical","exploited":false,"published_at":"2026-06-17T17:16:50.727+00:00","url":"https://junglewise.ai/threats/cve-2026-3490-picklescan-blocklist-bypass-via-pkgutil-resolve-name"},{"cvss":10,"slug":"picklescan-blocklist-bypass-via-pkgutil-resolve-name-74c87206","title":"PickleScan blocklist bypass via pkgutil.resolve_name","severity":"critical","exploited":false,"published_at":"2026-06-17T18:35:57+00:00","url":"https://junglewise.ai/threats/picklescan-blocklist-bypass-via-pkgutil-resolve-name-74c87206"},{"cve":"CVE-2026-56315","cvss":9.8,"epss":0.0115,"slug":"cve-2026-56315-picklescan-remote-code-execution-via-unblocked-standard-library","title":"picklescan remote code execution via unblocked standard library modules","severity":"critical","exploited":false,"published_at":"2026-06-23T13:16:45.77+00:00","url":"https://junglewise.ai/threats/cve-2026-56315-picklescan-remote-code-execution-via-unblocked-standard-library"},{"cve":"CVE-2026-53874","cvss":9.8,"epss":0.0076,"slug":"cve-2026-53874-picklescan-unsafe-deserialization-via-obfuscated-eval-call","title":"picklescan unsafe deserialization via obfuscated eval call","severity":"critical","exploited":false,"published_at":"2026-06-17T17:17:25.733+00:00","url":"https://junglewise.ai/threats/cve-2026-53874-picklescan-unsafe-deserialization-via-obfuscated-eval-call"},{"cve":"CVE-2025-71323","cvss":9.8,"epss":0.0076,"slug":"cve-2025-71323-picklescan-remote-code-execution-via-unblocked-ctypes-module","title":"picklescan remote code execution via unblocked ctypes module","severity":"critical","exploited":false,"published_at":"2026-06-17T17:16:41.11+00:00","url":"https://junglewise.ai/threats/cve-2025-71323-picklescan-remote-code-execution-via-unblocked-ctypes-module"},{"cve":"CVE-2026-53873","cvss":9.8,"epss":0.0067,"slug":"cve-2026-53873-picklescan-incomplete-blocklist-bypass-in-profile-module","title":"picklescan incomplete blocklist bypass in profile module","severity":"critical","exploited":false,"published_at":"2026-06-17T17:17:25.607+00:00","url":"https://junglewise.ai/threats/cve-2026-53873-picklescan-incomplete-blocklist-bypass-in-profile-module"},{"cve":"CVE-2025-71321","cvss":9.8,"epss":0.0062,"slug":"cve-2025-71321-picklescan-arbitrary-file-write-via-distutils-blocklist-bypass","title":"Picklescan arbitrary file write via distutils blocklist bypass","severity":"critical","exploited":false,"published_at":"2026-06-17T17:16:40.847+00:00","url":"https://junglewise.ai/threats/cve-2025-71321-picklescan-arbitrary-file-write-via-distutils-blocklist-bypass"},{"cve":"CVE-2025-71320","cvss":9.8,"epss":0.0062,"slug":"cve-2025-71320-picklescan-incomplete-deny-list-bypass-leading-to-rce","title":"picklescan incomplete deny-list bypass leading to RCE","severity":"critical","exploited":false,"published_at":"2026-06-17T17:16:40.697+00:00","url":"https://junglewise.ai/threats/cve-2025-71320-picklescan-incomplete-deny-list-bypass-leading-to-rce"},{"cve":"CVE-2025-71325","cvss":9.8,"epss":0.0048,"slug":"cve-2025-71325-picklescan-detection-bypass-in-stack-global-opcode-parsing","title":"picklescan detection bypass in STACK_GLOBAL opcode parsing","severity":"critical","exploited":false,"published_at":"2026-06-17T17:16:41.247+00:00","url":"https://junglewise.ai/threats/cve-2025-71325-picklescan-detection-bypass-in-stack-global-opcode-parsing"},{"cvss":9.8,"slug":"picklescan-incomplete-blocklist-rce-via-stdlib-modules-3e253cc3","title":"PickleScan incomplete blocklist RCE via stdlib modules","severity":"critical","exploited":false,"published_at":"2026-06-23T15:32:36+00:00","url":"https://junglewise.ai/threats/picklescan-incomplete-blocklist-rce-via-stdlib-modules-3e253cc3"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}