VYPR

Picklescan

by Pypi

CVEs (2)

  • CVE-2025-71357Jun 21, 2026
    risk 0.00cvss epss

    picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.

  • CVE-2025-71351Jun 21, 2026
    risk 0.00cvss epss

    picklescan before 0.0.25 fails to detect malicious pickle files that use timeit.timeit() in the __reduce__ method, allowing remote code execution. Attackers can craft pickle files that import dangerous libraries like os and execute arbitrary system commands, which evade…