High severity8.1NVD Advisory· Published Jun 23, 2026· Updated Jun 23, 2026
CVE-2025-71365
CVE-2025-71365
Description
picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.myeval function through the reduce method. Attackers can craft malicious pickle files embedding arbitrary code that evades picklescan detection and executes remote code when loaded.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <0.0.33
Patches
Vulnerability mechanics
References
2News mentions
1- Picklescan: Nine RCE Vulnerabilities Disclosed Together via Detection BypassesVypr Intelligence · Jun 23, 2026