High severityNVD Advisory· Published Jun 17, 2026· Updated Jun 17, 2026
picklescan - Arbitrary File Writing via distutils Module Bypass
CVE-2025-71321
Description
picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects to overwrite critical system files and achieve denial of service or remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
picklescanPyPI | < 0.0.33 | 0.0.33 |
Affected products
1- Range: <0.0.33
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-m273-6v24-x4m4ghsaADVISORY
- github.com/mmaitre314/picklescan/security/advisories/GHSA-m273-6v24-x4m4ghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-71321ghsaADVISORY
- www.vulncheck.com/advisories/picklescan-arbitrary-file-writing-via-distutils-module-bypassghsathird-party-advisoryWEB
- github.com/mmaitre314/picklescan/commit/70c1c6c31beb6baaf52c8db1b6c3c0e84a6f9dabghsaWEB
- github.com/mmaitre314/picklescan/pull/53ghsaWEB
- github.com/mmaitre314/picklescan/releases/tag/v0.0.33ghsaWEB
News mentions
0No linked articles in our index yet.