PyPi: Picklescan

CVE-2025-1716

Safety vulnerability ID: 76321

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Feb 26, 2025 Updated at Mar 28, 2025
Scan your Python projects for vulnerabilities →

Advisory

An unsafe deserialization vulnerability in Python’s pickle module allows an attacker to bypass static analysis tools like Picklescan and execute arbitrary code during deserialization. This can be exploited to run pip install and fetch a malicious package, enabling remote code execution (RCE) upon package installation.

Affected package

picklescan

Latest version: 0.0.24

Security scanner detecting Python Pickle files performing suspicious actions

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application