CVE-2025-71373 - picklescan - Remote Code Execution via operator.methodcaller Detection Bypass
CVE ID :CVE-2025-71373
Published : July 4, 2026, 2:16 a.m. | 4 hours, 28 minutes ago
Description :picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads using operator.methodcaller that execute arbitrary code when loaded, compromising systems relying on picklescan for validation.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 4, 2026, 2:16 a.m. | 4 hours, 28 minutes ago
Description :picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads using operator.methodcaller that execute arbitrary code when loaded, compromising systems relying on picklescan for validation.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...