picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.
References
Configurations
No configuration.
History
22 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/mmaitre314/picklescan/security/advisories/GHSA-j343-8v2j-ff7w - |
21 Jun 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-21 14:16
Updated : 2026-06-22 18:40
NVD link : CVE-2025-71357
Mitre link : CVE-2025-71357
CVE.ORG link : CVE-2025-71357
JSON object : View
Products Affected
No product.
CWE
CWE-502
Deserialization of Untrusted Data
