CVE-2025-71345 - picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_autograd_prof
CVE ID :CVE-2025-71345
Published : July 4, 2026, 2:16 a.m. | 8 hours, 28 minutes ago
Description :picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote code execution.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 4, 2026, 2:16 a.m. | 8 hours, 28 minutes ago
Description :picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote code execution.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...