📦 Picklescan

by Mmaitre314

🔍 What is Picklescan?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-10156

CRITICAL CVSS 9.8 Sep 17, 2025

This vulnerability allows attackers to bypass security scans in mmaitre314 picklescan by crafting ZIP archives with bad CRC values. When exploited, malicious pickle files can evade detection and execu...

CVE-2025-1945

CRITICAL CVSS 9.8 Mar 10, 2025

CVE-2025-1945 is a vulnerability in picklescan versions before 0.0.23 that allows attackers to bypass security scanning by embedding malicious pickle files in PyTorch model archives with modified ZIP ...

CVE-2025-1889

CRITICAL CVSS 9.8 Mar 3, 2025

CVE-2025-1889 is a vulnerability in picklescan versions before 0.0.22 where the tool only checks standard pickle file extensions (.pkl, .pickle, .pckl) for malicious content. Attackers can bypass secu...

CVE-2025-1716

CRITICAL CVSS 9.8 Feb 26, 2025

CVE-2025-1716 is a critical vulnerability in picklescan versions before 0.0.21 where the tool fails to restrict the 'pip' global during pickle file scanning. This allows attackers to embed malicious c...

CVE-2025-10157

HIGH CVSS 7.8 Sep 17, 2025

This vulnerability allows attackers to bypass picklescan's unsafe globals check by using submodule imports instead of exact package names. Attackers can load malicious pickle files that appear safe du...

CVE-2025-10155

HIGH CVSS 7.8 Sep 17, 2025

This vulnerability allows attackers to bypass security checks in picklescan by disguising malicious pickle files with PyTorch-related extensions. When these files are incorrectly marked as safe and lo...

CVE-2025-46417

HIGH CVSS 7.5 Apr 24, 2025

This vulnerability in Picklescan versions before 0.0.25 allows data exfiltration via DNS requests after deserialization due to missing 'ssl' in unsafe globals. Attackers can exploit this to leak sensi...

CVE-2025-1944

MEDIUM CVSS 6.5 Mar 10, 2025

CVE-2025-1944 is a ZIP archive manipulation vulnerability in picklescan versions before 0.0.23 that allows malicious PyTorch model files to bypass security scanning. Attackers can craft archives with ...