CVE-2025-71374Patch

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files that bypass picklescan detection and achieve code execution upon deserialization.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2025-71374 (CVSS 8.1) picklescan <0[.]0[.]29 fails to detect malicious pickle files using profile[.]Profile[.]run, enabling RCE via deserialization. ✅ Update to v0[.]0[.]29+ #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/GUg8T8DCMk

    Post summary

    The post highlights a high‑severity RCE vulnerability in picklescan, provides technical details, and urges users to upgrade to v0.0.29 or newer.

    0000047
    56 followersView on X

Explore more