VYPR
High severity8.1NVD Advisory· Published Jun 21, 2026· Updated Jun 26, 2026

CVE-2025-71348

CVE-2025-71348

Description

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply chain attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:*range: <0.0.28
    • (no CPE)range: <0.0.28

Patches

Vulnerability mechanics

References

8

News mentions

1