Unrated severityNVD Advisory· Published Jun 21, 2026
picklescan - Arbitrary Code Execution via torch.utils._config_module.load_config Bypass
CVE-2025-71348
Description
picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply chain attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <0.0.28
Patches
Vulnerability mechanics
References
2News mentions
1- Picklescan: Nine RCE Vulnerabilities Disclosed Together via Detection BypassesVypr Intelligence · Jun 23, 2026