PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-71352 picklescan CVE debrief

CVE-2025-71352 is a high-severity vulnerability in the picklescan library before version 0.0.29. The vulnerability allows remote attackers to execute arbitrary code by crafting malicious pickle files with trace.Trace.runctx payloads that bypass picklescan detection. This occurs when picklescan fails to detect the built-in Python trace.Trace.runctx function used in pickle file reduce methods.

Vendor
picklescan
Product
Unknown
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-30
Original CVE updated
2026-10-05
Advisory published
2026-06-30
Advisory updated
2026-10-05

Who should care

Defenders responsible for systems and applications using the picklescan library should assess exposure and prioritize verification and remediation efforts. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify picklescan versions, review system inventories, and assess potential exposure to malicious pickle files.

Why it matters

CVE-2025-71352 is a high-severity vulnerability in picklescan that allows remote code execution via malicious pickle files. Defenders should prioritize verification and remediation efforts, focusing on updating picklescan and restricting untrusted pickle file loading.

  • Remote code execution upon loading malicious pickle files
  • Potential for arbitrary code execution in vulnerable applications
  • Need for verification of picklescan version and inventory checks
  • Priority for updating picklescan to version 0.0.29 or later

Technical summary

The picklescan library before version 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce methods. This allows attackers to craft malicious pickle files with trace.Trace.runctx payloads that bypass picklescan detection and execute code upon pickle.load() invocation. The vulnerability affects systems and applications using the picklescan library, particularly those loading untrusted pickle files. Defenders should prioritize verifying and updating picklescan to version 0.0.29 or later.

Defensive priority

Defenders should prioritize verifying and updating picklescan to version 0.0.29 or later, and restrict the loading of untrusted pickle files.

Recommended defensive actions

  • Verify and update picklescan to version 0.0.29 or later
  • Restrict the loading of untrusted pickle files
  • Monitor for suspicious pickle file activity
  • Review system inventories for potential exposure
  • Verify picklescan versions in use
  • Assess potential impact of vulnerability on managed environments
  • Track exceptions and retest remediated assets

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but the scope of affected versions and potential impact require further verification from official sources. Defenders should verify picklescan versions, review system inventories, and assess potential exposure to malicious pickle files. Additional verification is needed to confirm the full scope of affected systems and potential impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-71352 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-71352

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-71352 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-71352

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/mmaitre314/picklescan/security/advisories/GHSA-g344-hcph-8vgg

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/picklescan-remote-code-execution-via-undetected-trace-trace-runctx-in-pickle-files

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.