216.73.216.133

CVE-2025-71369

· Published 04/07/2026 04:16 · Author: The MITRE Corporation

Labels: CVE-2025-71369

Essential information

Published
04/07/2026 04:16
Modified
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
8.1 HIGH (v3.1) 7.6 HIGH (v4.0)
CISA KEV
No
CWE
CWE-502
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CVSS metrics

Description

picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing attackers to bypass safety checks. Remote attackers can embed undetected malicious code in pickle files that executes during deserialization, enabling remote code execution.

NVD status

NVD
View on NVD