VYPR
Unrated severityNVD Advisory· Published Jun 21, 2026

picklescan - Arbitrary Code Execution via torch.utils._config_module.load_config Bypass

CVE-2025-71348

Description

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply chain attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

1