CVE-2025-71355

Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass static analysis and execute arbitrary code during deserialization. Attackers can craft malicious pickle files using numpy.testing._private.utils.runstring within the reduce method to import dangerous libraries like os and execute arbitrary OS commands when the pickle file is loaded.
CVSS

No CVSS.

Configurations

No configuration.

History

01 Jul 2026, 16:16

Type Values Removed Values Added
References () https://github.com/mmaitre314/picklescan/security/advisories/GHSA-fj43-3qmq-673f - () https://github.com/mmaitre314/picklescan/security/advisories/GHSA-fj43-3qmq-673f -

30 Jun 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-30 23:16

Updated : 2026-07-01 18:21


NVD link : CVE-2025-71355

Mitre link : CVE-2025-71355

CVE.ORG link : CVE-2025-71355


JSON object : View

Products Affected

No product.

CWE
CWE-184

Incomplete List of Disallowed Inputs