CVE-2025-71375
picklescan - Undetected Remote Code Execution via _operator.methodcaller
Vexday Risk Score
18Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.6EPSS —KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
04 Jul 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load().
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
picklescan · picklescan