
In 2025 the standard model scanner (picklescan) got bypassed so badly that renaming a file defeated it. CVE-2025-10155 (CVSS 9.3): rename malicious.pkl → model.safetensors and the extension-based check just… skipped it. Fails open. The lesson is 40 years old. 🧵 https://t.co/a1zUHz8tdg
Post summary
The tweet discloses CVE-2025-10155, a high‑severity flaw in picklescan that can be bypassed by renaming a malicious pickle file to a safetensors extension, and notes the vulnerability’s CVSS score of 9.3.

