← back
CVE-2025-71321

picklescan - Arbitrary File Writing via distutils Module Bypass

CVSS 9.3 CRITICALEPSS 0.6%CWE-502
picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects to overwrite critical system files and achieve denial of service or remote code execution.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
picklescan · picklescan

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →