picklescan
PyPI58 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting picklescanpage 2 of 2
- CVE-2025-71378HIGHCVSS 7.8EG 8.1✓ Fixed in 0.0.302026-06-21
vulnerable: 0.0.1 ... 0.0.9 (29 versions)
picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass picklescan detection and execute remote code when loaded via…
- CVE-2026-3490CRITICALCVSS 10.0EG 10.0✓ Fixed in 1.0.42026-06-17
vulnerable: 0.0.1 ... 1.0.3 (39 versions)
picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function through indirect REDUCE calls. Remote attackers can invoke any blocked function such as os.s…
- CVE-2026-53872HIGHCVSS 7.5EG 7.5✓ Fixed in 0.0.352026-06-17
vulnerable: 0.0.1 ... 0.0.9 (34 versions)
picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to read arbitrary server files by chaining io.FileIO and urllib.request.urlopen. Attackers can bypass RCE-focused blocklist…
- CVE-2026-53873CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.0.42026-06-17
vulnerable: 0.0.1 ... 1.0.3 (39 versions)
picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowing attackers to achieve arbitrary code execution via exec(). Attackers can craft malicious p…
- CVE-2026-53874CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.0.12026-06-17
vulnerable: 0.0.1 ... 1.0.0 (36 versions)
picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attackers can embed malicious code in pickle …
- CVE-2026-53875HIGHCVSS 7.1EG 7.1✓ Fixed in 1.0.32026-06-17
vulnerable: 0.0.1 ... 1.0.2 (38 versions)
picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to embed malicious magic numbers via dynamic eval using the __reduce__ trick. Attackers can craft malicious PyTorch payload…
- CVE-2026-56304MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.0.12026-06-20
vulnerable: 0.0.1 ... 1.0.0 (36 versions)
picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte files via logging.FileHandler class instantiation. Attackers can exploit this by crafting mali…
- CVE-2026-56315CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.0.42026-06-23
vulnerable: 0.0.1 ... 1.0.3 (39 versions)
picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib) exposing eight functions that provide direct arbitrary command execution. Attack…
Check whether picklescan is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for picklescan CVEs against the assets you own.
Start Free Scan →