CVE-2025-71321

picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects to overwrite critical system files and achieve denial of service or remote code execution.
Configurations

No configuration.

History

17 Jun 2026, 20:21

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 17:16

Updated : 2026-06-17 20:21


NVD link : CVE-2025-71321

Mitre link : CVE-2025-71321

CVE.ORG link : CVE-2025-71321


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data