Back to CVE List

CVE-2025-71361

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.1 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Vulnerability Description

picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote code execution. Attackers can embed undetected payloads in pickle files that execute arbitrary code when loaded via pickle.load().

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-95
Source
NVD
Vendor
picklescan
Product
picklescan

External References

Discussion (0)

Add Comment

No comments yet. Be the first!