High severityNVD Advisory· Published Jun 17, 2026· Updated Jun 17, 2026
picklescan - Remote Code Execution via Unblocked ctypes Module
CVE-2025-71323
Description
picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls and accessing raw memory. Attackers can craft malicious pickle files using ctypes.WinDLL to load kernel32.dll and execute arbitrary commands, bypassing sandbox protections and gadget chain detection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
picklescanPyPI | < 0.0.33 | 0.0.33 |
Affected products
1- Range: <0.0.33
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-4675-36f9-wf6rghsaADVISORY
- github.com/mmaitre314/picklescan/security/advisories/GHSA-4675-36f9-wf6rghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-71323ghsaADVISORY
- www.vulncheck.com/advisories/picklescan-remote-code-execution-via-unblocked-ctypes-moduleghsathird-party-advisoryWEB
- github.com/mmaitre314/picklescan/commit/70c1c6c31beb6baaf52c8db1b6c3c0e84a6f9dabghsaWEB
- github.com/mmaitre314/picklescan/pull/53ghsaWEB
- github.com/mmaitre314/picklescan/releases/tag/v0.0.33ghsaWEB
News mentions
0No linked articles in our index yet.