All 34 CVE vulnerabilities found in picklescan, with AI-generated Chinese analysis, references, and POCs.
This page documents security vulnerabilities associated with picklescan, a Python library designed for scanning pickle data for security risks. It aggregates reported weaknesses from various vendors and security databases, providing a comprehensive overview of the risks linked to this specific tool and its underlying dependencies. The collection covers vulnerabilities disclosed between January 2023 and October 2024, ensuring that both recent and historical security issues are accessible for analysis. By consolidating data from multiple sources, this resource aims to provide a clear and unified view of the security landscape surrounding picklescan. Users can utilize this page to track advisories issued by specific vendors, allowing them to stay informed about patches and mitigation strategies. Furthermore, the page facilitates a deeper understanding of common weakness classifications, helping developers identify patterns in how similar vulnerabilities are reported and addressed across different contexts. Readers can also look up the complete vulnerability history of picklescan, examining how the product's security posture has evolved over time. This historical perspective is crucial for assessing long-term stability and reliability. The information provided is intended for security professionals, developers, and IT administrators who need to evaluate the risk of using picklescan in their environments. By presenting aggregated data in a structured format, the page supports informed decision-making regarding software procurement and security audits. It serves as a reference point for understanding the specific threat models associated with pickle serialization and how picklescan addresses these concerns through its design and implementation.
Vendor: mmaitre314
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-1945 | picklescan - Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch CWE-345 | 9.8 | - | 2025-03-10 |
| CVE-2025-1944 | picklescan ZIP archive manipulation attack leads to crash CWE-345 | 7.5 | - | 2025-03-10 |
| CVE-2025-1889 | picklescan - Security scanning bypass via non-standard file extensions CWE-646 | 7.5 | - | 2025-03-03 |
| CVE-2025-1716 | picklescan - Security scanning bypass via 'pip main' CWE-184 | 8.1 | - | 2025-02-26 |
All 34 known CVE vulnerabilities affecting picklescan with full Chinese analysis, references, and POCs where available.