PT-2026-50451 · Pypi · Picklescan

·

CVE-2025-71320

·

Published

2025-12-29

·

Updated

2026-07-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions picklescan versions prior to 0.0.33
Description An incomplete deny-list fails to block the pydoc.locate() and operator.methodcaller() functions. This allows remote attackers to bypass security checks by crafting malicious pickle files. The pydoc.locate() function can dynamically resolve and import arbitrary modules, while operator.methodcaller() enables the execution of a method on an object. When combined, these functions can be used to achieve arbitrary code execution during the deserialization of the pickle file.
Recommendations Update to version 0.0.33 or later.

Exploit

Fix

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71320
GHSA-6V84-V468-3C7F
GHSA-84R2-JW7C-4R5Q
PYSEC-2026-1785

Affected Products

Picklescan