7.6
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Description
picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using profile.Profile.runctx in the reduce method to achieve remote code execution when the pickle file is loaded.
Basic Information
ID
CVE-2025-71341
Source
VulnCheck
Published
Jun 23, 2026 at 12:12
Affected Product
Vendor
picklescan
Product
picklescan
Affected Versions
picklescan picklescan 0