Unrated severityNVD Advisory· Published Jul 4, 2026· Updated Jul 7, 2026
picklescan - Arbitrary Code Execution via lib2to3.pgen2.pgen.ParserGenerator.make_label Detection Bypass
CVE-2025-71343
Description
picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. Attackers can craft malicious pickle files with embedded code that evades detection but executes arbitrary commands when pickle.load() is called.
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.