CVE-2025-71375 - picklescan - Undetected Remote Code Execution via _operator.methodcaller
CVE ID :CVE-2025-71375
Published : July 4, 2026, 2:16 a.m. | 4 hours, 28 minutes ago
Description :picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load().
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 4, 2026, 2:16 a.m. | 4 hours, 28 minutes ago
Description :picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load().
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...