picklescan
PyPI5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting picklescanpage 1 of 1
- CVE-2025-10157HIGHCVSS 7.8EG 7.8✓ Fixed in 0.0.312025-09-17
vulnerable: 0.0.1 ... 0.0.9 (30 versions)
A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check. This is possible because the scanner performs an exact match for module …
- CVE-2025-1716CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.0.222025-02-26
vulnerable: 0.0.1 ... 0.0.9 (21 versions)
picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for example, on pypi.org or GitHub) via `pip.main()`. Because pip is…
- CVE-2025-1944MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.0.232025-03-10
vulnerable: 0.0.1 ... 0.0.9 (22 versions)
picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model archives. By modifying the filename in the ZIP header while keeping the original filename…
- CVE-2025-1945CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.0.232025-03-10
vulnerable: 0.0.1 ... 0.0.9 (22 versions)
picklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag bits are modified. By flipping specific bits in the ZIP file headers, an attacker can embed malicious pickle files tha…
- CVE-2025-46417HIGHCVSS 7.5EG 7.5✓ Fixed in 0.0.252025-04-24
vulnerable: 0.0.1 ... 0.0.9 (24 versions)
The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization.
Check whether picklescan is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for picklescan CVEs against the assets you own.
Start Free Scan →