CVE-2026-53875 - picklescan - Scanning Bypass via Dynamic Eval in scan_pytorch
CVE ID :CVE-2026-53875
Published : June 17, 2026, 3:05 p.m. | 2 hours, 33 minutes ago
Description :picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to embed malicious magic numbers via dynamic eval using the __reduce__ trick. Attackers can craft malicious PyTorch payloads that evade picklescan detection while remaining executable, enabling arbitrary code execution when loaded with torch.load().
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 17, 2026, 3:05 p.m. | 2 hours, 33 minutes ago
Description :picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to embed malicious magic numbers via dynamic eval using the __reduce__ trick. Attackers can craft malicious PyTorch payloads that evade picklescan detection while remaining executable, enabling arbitrary code execution when loaded with torch.load().
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...