Unrated severityNVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026
picklescan - Arbitrary Code Execution via Undetected doctest.debug_script
CVE-2025-71368
Description
picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files embedding doctest.debug_script calls that bypass picklescan detection and execute arbitrary commands upon pickle.load invocation.
Patches
Vulnerability mechanics
References
2- github.com/mmaitre314/picklescan/security/advisories/GHSA-fqq6-7vqf-w3fgmitrevendor-advisory
- www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-undetected-doctest-debug-scriptmitrethird-party-advisory
News mentions
0No linked articles in our index yet.