CVE-2025-71371

picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce methods. Attackers can craft pickle payloads that bypass picklescan detection and execute arbitrary code when loaded via pickle.load().
Configurations

No configuration.

History

01 Jul 2026, 15:16

Type Values Removed Values Added
References () https://github.com/mmaitre314/picklescan/security/advisories/GHSA-cj3c-v495-4xqh - () https://github.com/mmaitre314/picklescan/security/advisories/GHSA-cj3c-v495-4xqh -

30 Jun 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-30 23:16

Updated : 2026-07-01 18:21


NVD link : CVE-2025-71371

Mitre link : CVE-2025-71371

CVE.ORG link : CVE-2025-71371


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data