GHSA-6556-fwc2-fg2pMediumCVSS 8.1

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length

Published
December 30, 2025
Last Modified
July 18, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

Picklescan uses the numpy.f2py.crackfortran._eval_length function (a NumPy F2PY helper) to execute arbitrary Python code during unpickling.

Details

Picklescan fails to detect a malicious pickle that uses the gadget numpy.f2py.crackfortran._eval_length in __reduce__, allowing arbitrary command execution when the pickle is loaded. A crafted object returns this function plus attacker‑controlled arguments; the scan reports the file as safe, but pickle.load() triggers execution.

PoC

class PoC:
    def __reduce__(self):
        from numpy.f2py.crackfortran import _eval_length
        return _eval_length, ("__import__('os').system('whoami')", None)

Impact

  • Arbitrary code execution on the victim machine once they load the “scanned as safe” pickle / model file.
  • Affects any workflow relying on Picklescan to vet untrusted pickle / PyTorch artifacts.
  • Enables supply‑chain poisoning of shared model files.

Credits

🎯 Affected products1

  • pip/picklescan:< 0.0.33

🔗 References (10)