PT-2026-51763 · Picklescan · Picklescan
Fredericdt
·
Published
2026-06-24
·
Updated
2026-06-24
·
CVE-2025-71361
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch tip calls in pickle files, allowing remote code execution. Attackers can embed undetected payloads in pickle files that execute arbitrary code when loaded via pickle.load().
Fix
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Picklescan