VYPR
Critical severity9.8NVD Advisory· Published Feb 26, 2025· Updated Jun 17, 2026

CVE-2025-1716

CVE-2025-1716

Description

picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for example, on pypi.org or GitHub) via pip.main(). Because pip is not a restricted global, the model, when scanned with picklescan, would pass security checks and appear to be safe, when it could instead prove to be problematic.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
picklescanPyPI
< 0.0.220.0.22

Affected products

3
  • cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:*range: <0.0.22
    • (no CPE)range: 0.0.1
  • ghsa-coords
    Range: < 0.0.22

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.