CVE-2025-71352General

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files with trace.Trace.runctx payloads that bypass picklescan detection and execute code upon pickle.load() invocation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Mohi@disismohi
    General

    Your pickle scanner just missed the RCE. CVE-2025-71352: picklescan <0.0.29 doesn't catch trace.Trace.runctx in reduce methods. Attacker ships a .pkl, scanner says clean, you load it, they run code.

    Post summary

    The tweet alerts that picklescan versions below 0.0.29 miss the RCE in CVE‑2025‑71352 due to trace.Trace.runctx in reduce methods, highlighting a detection gap.

    1000049
    69 followersView on X

Explore more