picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.
References
| Link | Resource |
|---|---|
| https://github.com/mmaitre314/picklescan/security/advisories/GHSA-j343-8v2j-ff7w | Exploit Vendor Advisory |
| https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-undetected-idlelib-pyshell-modifiedinterpreter-runcommand | Third Party Advisory |
| https://github.com/mmaitre314/picklescan/security/advisories/GHSA-j343-8v2j-ff7w | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-06-21 14:16
Updated : 2026-06-26 14:14
NVD link : CVE-2025-71357
Mitre link : CVE-2025-71357
CVE.ORG link : CVE-2025-71357
JSON object : View
Products Affected
mmaitre314
- picklescan
CWE
CWE-502
Deserialization of Untrusted Data
