CVE-2025-71355

Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass static analysis and execute arbitrary code during deserialization. Attackers can craft malicious pickle files using numpy.testing._private.utils.runstring within the reduce method to import dangerous libraries like os and execute arbitrary OS commands when the pickle file is loaded.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-06-30 23:16

Updated : 2026-07-01 18:21


NVD link : CVE-2025-71355

Mitre link : CVE-2025-71355

CVE.ORG link : CVE-2025-71355


JSON object : View

Products Affected

No product.

CWE
CWE-184

Incomplete List of Disallowed Inputs