CVE-2025-71378EPSS p26.3%
CVE-2025-71378CVE-2025-71378
mmaitre314 / picklescan
Description
picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection and execute remote code when loaded via pickle.load().
Scoring
| CVSS | 8.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
| EPSS | 0.34% probability of exploitation · percentile 26.3% · 2026-08-06T12:00:30Z |
| Last modified | 2026-06-26 |