VYPR

picklescan

by mmaitre314

pypi: picklescan

Source repositories

CVEs (24)

  • CVE-2025-1945Mar 10, 2025
    risk 0.00cvss epss 0.01

    picklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag bits are modified. By flipping specific bits in the ZIP file headers, an attacker can embed malicious pickle files that remain undetected by PickleScan while…

  • CVE-2025-1944Mar 10, 2025
    risk 0.00cvss epss 0.00

    picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model archives. By modifying the filename in the ZIP header while keeping the original filename in the directory listing, an attacker…

  • CVE-2025-1889Mar 3, 2025
    risk 0.00cvss epss 0.00

    picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and include a malicious pickle file with a non-standard file extension. Because the malicious pickle file…

  • CVE-2025-1716Feb 26, 2025
    risk 0.00cvss epss 0.01

    picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for example, on pypi.org or GitHub) via `pip.main()`. Because pip is not a restricted global, the model,…

Page 2 of 2