216.73.216.133

CVE-2025-71347

· Published 04/07/2026 04:16 · Author: The MITRE Corporation

Labels: CVE-2025-71347

Essential information

Published
04/07/2026 04:16
Modified
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
8.1 HIGH (v3.1) 7.6 HIGH (v4.0)
CISA KEV
No
CWE
CWE-502
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CVSS metrics

Description

picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. Remote attackers can embed undetected code in pickle files that executes during deserialization, enabling arbitrary code execution in applications loading untrusted pickle data.

NVD status

NVD
View on NVD