CVE-2025-71342Disclosure

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in PyTorch models and supply chain attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-06: 1Technical Details · 2026-07-06: 107-06
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Mohi@disismohi
    Disclosure

    If you're scanning PyTorch models with picklescan, you have a blind spot. CVE-2025-71342 is a scanner bypass that lets attackers embed undetected code in pickle files. Here's what to check Monday.

    Post summary

    CVE-2025-71342 is a scanner bypass that allows attackers to embed hidden code into PyTorch pickle files, bypassing picklescan checks.

    1000059
    71 followersView on X

Explore more