VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2025-71342

CVE-2025-71342: picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. A

Published Jul 4, 2026 CVSS 7.6

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in PyTorch models and supply chain attacks.

Affected AI Products

pytorch
Get the weekly digest. Every Monday: top AI security stories of the week. Free.