CVE-2025-71354
HIGH8.1CVSS v3
—CVSS v2
0.25%
EPSS (exploit probability)
CWE-502CWE
Description
picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in reduce methods. Attackers can craft pickle files with embedded code that bypasses picklescan detection and executes arbitrary commands when pickle.load() is called.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.