Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

picklescan — Vulnerabilities & Security Advisories 58

All 58 CVE vulnerabilities found in picklescan, with AI-generated Chinese analysis, references, and POCs.

The picklescan vulnerability aggregation page catalogues security weaknesses associated with the Python-based static analysis tool designed for testing pickle and unpickle operations. This resource compiles a comprehensive dataset of reported vulnerabilities affecting the picklescan software, covering security incidents from its initial release through the present day. By centralizing this information, the page enables security professionals to efficiently track vendor advisories as they are issued, providing a clear timeline of how specific issues were identified and remediated over time. Users can explore detailed analyses of distinct weakness classes to understand the underlying technical flaws, such as deserialization risks or improper input validation, that are specific to this tool’s architecture. Additionally, the page serves as a historical record for the product, allowing investigators to look up the complete vulnerability history of picklescan. This includes examining the evolution of security patches, the frequency of updates, and the overall security posture of the application. Whether you are a developer seeking to patch your instance, a security auditor verifying compliance, or a researcher analyzing trends in Python serialization tools, this aggregation provides the necessary context to make informed decisions. The data is organized to facilitate easy navigation through different vulnerability types and release versions, ensuring that stakeholders can quickly locate relevant information without sifting through unrelated noise. This focused approach helps mitigate risks by highlighting past mistakes and current best practices for securing similar utilities.

Vendor: mmaitre314

CVE IDTitleCVSSSeverityPublished
CVE-2025-71375 picklescan - Undetected Remote Code Execution via _operator.methodcaller CWE-502 8.1 High2026-07-04
CVE-2025-71372 Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.getlincoef Gadget CWE-502 8.1 High2026-07-04
CVE-2025-71373 picklescan - Remote Code Execution via operator.methodcaller Detection Bypass CWE-693 8.1 High2026-07-04
CVE-2025-71369 picklescan - Unsafe Deserialization via torch.utils.data.datapipes.utils.decoder.basichandlers CWE-502 8.1 High2026-07-04
CVE-2025-71367 picklescan - Remote Code Execution via _operator.attrgetter Detection Bypass CWE-502 8.1 High2026-07-04
CVE-2025-71366 picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_cprofile CWE-502 8.1 High2026-07-04
CVE-2025-71364 picklescan - Arbitrary Code Execution via Undetected asyncio.unix_events._UnixSubprocessTransport._start CWE-502 8.1 High2026-07-04
CVE-2025-71360 picklescan - Remote Code Execution via Undetected idlelib.calltip.get_entity CWE-502 8.1 High2026-07-04
CVE-2025-71362 picklescan - Arbitrary Code Execution via Unsafe Deserialization in numpy.f2py.crackfortran CWE-502 8.1 High2026-07-04
CVE-2025-71359 picklescan - Unsafe Deserialization via lib2to3.pgen2.grammar.Grammar.loads CWE-502 8.1 High2026-07-04
CVE-2025-71356 picklescan - Arbitrary Code Execution via torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression CWE-502 8.1 High2026-07-04
CVE-2025-71353 picklescan - Remote Code Execution via torch._dynamo.guards.GuardBuilder.get CWE-502 8.1 High2026-07-04
CVE-2025-71347 picklescan - Undetected Remote Code Execution via numpy.f2py.crackfortran.param_eval CWE-502 8.1 High2026-07-04
CVE-2025-71345 picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_autograd_prof CWE-502 8.1 High2026-07-04
CVE-2025-71342 picklescan - Undetected Remote Code Execution via idlelib.run.Executive.runcode CWE-502 8.1 High2026-07-04
CVE-2025-71343 picklescan - Arbitrary Code Execution via lib2to3.pgen2.pgen.ParserGenerator.make_label Detection Bypass CWE-502 8.1 High2026-07-04
CVE-2025-71374 picklescan - Arbitrary Code Execution via Undetected profile.Profile.run CWE-502 8.1 High2026-06-30
CVE-2025-71371 picklescan - Remote Code Execution via code.InteractiveInterpreter Detection Bypass CWE-502 8.1 High2026-06-30
CVE-2025-71368 picklescan - Arbitrary Code Execution via Undetected doctest.debug_script CWE-502 8.1 High2026-06-30
CVE-2025-71363 picklescan - Arbitrary Code Execution via Undetected cProfile.run in Pickle Deserialization CWE-502 8.1 High2026-06-30
CVE-2025-71355 Picklescan - Arbitrary Code Execution via Unsafe Numpy Function Detection Bypass CWE-184--2026-06-30
CVE-2025-71350 picklescan - Undetected Remote Code Execution via torch.utils.collect_env.run CWE-502 8.1 High2026-06-30
CVE-2025-71352 picklescan - Remote Code Execution via Undetected trace.Trace.runctx in Pickle Files CWE-693 8.1 High2026-06-30
CVE-2025-71349 picklescan - Arbitrary Code Execution via Undetected trace.Trace.run in Pickle Files CWE-502 8.1 High2026-06-30
CVE-2025-71340 picklescan - Remote Code Execution via idlelib.pyshell.ModifiedInterpreter.runcode CWE-502 8.1 High2026-06-25
CVE-2025-71361 picklescan - Remote Code Execution via Undetected idlelib.calltip.Calltip.fetch_tip CWE-95 8.1 High2026-06-24
CVE-2025-71354 picklescan - Remote Code Execution via idlelib.debugobj.ObjectTreeItem.SetText CWE-502 8.1 High2026-06-24
CVE-2026-56315 picklescan - Remote Code Execution via Unblocked Standard Library Modules CWE-184 9.8 Critical2026-06-23
CVE-2025-71376 picklescan - Arbitrary Code Execution via Undetected idlelib.autocomplete.AutoComplete.fetch_completions CWE-502 8.1 High2026-06-23
CVE-2025-71370 picklescan - Remote Code Execution via torch.jit.unsupported_tensor_ops.execWrapper CWE-502 8.1 High2026-06-23

All 58 known CVE vulnerabilities affecting picklescan with full Chinese analysis, references, and POCs where available.