CVE-2025-10155General(mmaitre314 / picklescan)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the pickle file incorrectly considered safe is loaded, it can lead to the execution of malicious code.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • picklescan

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
picklescan

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-18: 1Mentions · 2026-07-10: 102-1807-10
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-181
General1
2026-07-101
Disclosure1
Full discourse2 posts
  • Mohit Kumar@mohitkr111
    Disclosure

    In 2025 the standard model scanner (picklescan) got bypassed so badly that renaming a file defeated it. CVE-2025-10155 (CVSS 9.3): rename malicious.pkl → model.safetensors and the extension-based check just… skipped it. Fails open. The lesson is 40 years old. 🧵 https://t.co/a1zUHz8tdg

    Post summary

    The tweet discloses CVE-2025-10155, a high‑severity flaw in picklescan that can be bypassed by renaming a malicious pickle file to a safetensors extension, and notes the vulnerability’s CVSS score of 9.3.

    2001055
    37 followersView on X
  • DailyCVE@dailycve
    General

    🔴 PyTorch, Scanning Bypass, #CVE-2025-10155 (Critical) https://dailycve.com/pytorch-scanning-bypass-cve-2025-10155-critical/

    Post summary

    The post announces CVE‑2025‑10155 as a critical scanning bypass vulnerability in PyTorch but offers no technical detail, exploit code, or evidence of active exploitation.

    0000030
    162 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmmaitre314picklescan---

Explore more