VulnWatch VulnWatch
← Back to dashboard
High github · GHSA-qvp4-q2p5-22gg

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config

Published Jun 21, 2026 CVSS 8.1

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-vv6j-3g6g-2pvj. This link is maintained to preserve external references.

Original Description

picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply chain attacks.

Affected AI Products

pytorch
Get the weekly digest. Every Monday: top AI security stories of the week. Free.