
Your pickle scanner just missed the RCE. CVE-2025-71352: picklescan <0.0.29 doesn't catch trace.Trace.runctx in reduce methods. Attacker ships a .pkl, scanner says clean, you load it, they run code.
Post summary
The tweet alerts that picklescan versions below 0.0.29 miss the RCE in CVE‑2025‑71352 due to trace.Trace.runctx in reduce methods, highlighting a detection gap.
