ZeroHour

CVE-2025-71378

PoC
CVSS 4.0
7.6 high
EPSS
<1%p40
Published
()
Modified
Description

picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection and execute remote code when loaded via pickle.load().

Vendors
mmaitre314
Products
picklescan
Ecosystems
pip
Weakness
CWE-502
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
GHSA
GHSA-9w88-8rmg-7g2p (medium)

In the news

No ingested article mentions this CVE yet.