← Volver al buscador de CVEs

CVE-2025-71341

picklescan

Descripción

picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using profile.Profile.runctx in the reduce method to achieve remote code execution when the pickle file is loaded.

CVSS 8.1EPSS 0.466%Riesgo 0.84
Ver fuente
Publicación
2026-06-23 13:16:38
Versiones afectadas
<0.0.29
Tipo
Librería
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N