CVE 7.6 HIGH

picklescan – Arbitrary Code Execution via torch.utils._config_module.load_config Bypass_CVE-2025-71348

7.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply chain attacks.

Basic Information

ID CVE-2025-71348
Source VulnCheck
Published Jun 21, 2026 at 13:26

Affected Product

Vendor picklescan
Product picklescan
Affected Versions picklescan picklescan 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.