CVE Explorer
CVE-2025-71351
picklescan before 0.0.25 fails to detect malicious pickle files that use timeit.timeit() in the __reduce__ method, allowing remote code execution. Attackers can craft pickle files that import dangerous libraries like os and execute arbitrary system commands, which evade picklescan detection and execute when pickle.load() is called.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","packageURL":"pkg:pypi/picklescan","product":"picklescan","vendor":"picklescan","versions":[{"lessThan":"0.0.25","status":"affected","version":"0","versionType":"semver"},{"status":"unaffected","version":"0.0.25","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7185e3390e757d51e473cf3994d4f5d1274b22b2689db550a53682acb4bf3e1d · sha256:d365951da74975b2… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":7.6,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7185e3390e757d51e473cf3994d4f5d1274b22b2689db550a53682acb4bf3e1d · sha256:d365951da74975b2… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-184","description":"Incomplete List of Disallowed Inputs","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7185e3390e757d51e473cf3994d4f5d1274b22b2689db550a53682acb4bf3e1d · sha256:d365951da74975b2… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"GHSA Advisory GHSA-v7x6-rv5q-mhwc","tags":["vendor-advisory"],"url":"https://github.com/mmaitre314/picklescan/security/advisories/GHSA-v7x6-rv5q-mhwc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7185e3390e757d51e473cf3994d4f5d1274b22b2689db550a53682acb4bf3e1d · sha256:d365951da74975b2… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/mmaitre314/picklescan/security/advisories/GHSA-v7x6-rv5q-mhwc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7185e3390e757d51e473cf3994d4f5d1274b22b2689db550a53682acb4bf3e1d · sha256:d365951da74975b2… · /containers/adp/0/references/0
{"name":"VulnCheck Advisory: picklescan - Remote Code Execution via timeit.timeit() Detection Bypass","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/picklescan-remote-code-execution-via-timeit-timeit-detection-bypass"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7185e3390e757d51e473cf3994d4f5d1274b22b2689db550a53682acb4bf3e1d · sha256:d365951da74975b2… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.