Unrated severityNVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026
picklescan - Undetected Remote Code Execution via torch.utils.collect_env.run
CVE-2025-71350
Description
picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.
Patches
Vulnerability mechanics
References
2- github.com/mmaitre314/picklescan/security/advisories/GHSA-f745-w6jp-hpxxmitrevendor-advisory
- www.vulncheck.com/advisories/picklescan-undetected-remote-code-execution-via-torch-utils-collect-env-runmitrethird-party-advisory
News mentions
0No linked articles in our index yet.