Skip to content
Threat Feed

Tag

Pickle

5 briefs RSS
high advisory

CVE-2025-71367: Picklescan Bypass Leading to Arbitrary Code Execution

Picklescan versions prior to 0.0.34 contain a deserialization vulnerability (CVE-2025-71367) that allows remote attackers to bypass security checks by crafting malicious pickle files using `_operator.attrgetter` in reduce methods, leading to arbitrary code execution when `pickle.load()` processes the file.

picklescan < 0.0.34 deserialization vulnerability python pickle rce
2t 1c
high advisory

CVE-2025-71342: picklescan Remote Code Execution Vulnerability

A critical vulnerability (CVE-2025-71342) exists in picklescan versions prior to 0.0.30, where it fails to detect malicious code embedded in Python pickle files by leveraging `idlelib.run.Executive.runcode` in reduce methods, allowing attackers to conceal and execute arbitrary code during `pickle.load` operations, leading to remote code execution (RCE) and potential supply chain attacks, particularly impacting PyTorch models.

picklescan < 0.0.30 vulnerability rce supply-chain python pickle pytorch
1t 1c
high advisory

Sentry 8.2.0 Remote Code Execution via Pickle Deserialization (CVE-2021-47935)

Sentry 8.2.0 contains a remote code execution vulnerability (CVE-2021-47935) that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter via crafted POST requests to the admin audit log endpoint.

Sentry 8.2.0 rce pickle deserialization sentry
2r 1t 1c
critical advisory

pyLoad Arbitrary Code Execution via Malicious Session Deserialization

pyLoad is vulnerable to arbitrary code execution via an unprotected `storage_folder` configuration option, allowing an attacker with `SETTINGS` and `ADD` permissions to write a malicious pickle payload to the Flask session store and execute arbitrary code upon subsequent HTTP requests.

pyLoad rce pickle deserialization webserver
2r 4t 1c 2i
high advisory

MONAI Library Vulnerable to Arbitrary Code Execution via Pickle Deserialization

The MONAI library is vulnerable to arbitrary code execution due to insecure deserialization of pickle files via the `algo_from_pickle` function, allowing attackers to execute arbitrary code by providing a malicious pickle file.

MONAI pickle rce insecure-deserialization python
2r 1t