High severity8.1NVD Advisory· Published Jun 21, 2026· Updated Jun 26, 2026
CVE-2025-71348
CVE-2025-71348
Description
picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply chain attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:*range: <0.0.28
- (no CPE)range: <0.0.28
Patches
Vulnerability mechanics
References
8- github.com/mmaitre314/picklescan/security/advisories/GHSA-vv6j-3g6g-2pvjnvdExploitVendor Advisory
- github.com/advisories/GHSA-vv6j-3g6g-2pvjghsaADVISORY
- www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-torch-utils-config-module-load-config-bypassnvdThird Party Advisory
- github.com/mmaitre314/picklescan/commit/7f994d62084fe43f1cffdef2f9bae6923344ef53ghsa
- github.com/mmaitre314/picklescan/pull/47ghsa
- github.com/mmaitre314/picklescan/releases/tag/v0.0.28ghsa
- github.com/pypa/advisory-database/tree/main/vulns/picklescan/PYSEC-2026-245.yamlghsa
- nvd.nist.gov/vuln/detail/CVE-2025-71348ghsa
News mentions
1- Picklescan: Nine RCE Vulnerabilities Disclosed Together via Detection BypassesVypr Intelligence · Jun 23, 2026