PatchSiren cyber security CVE debrief
CVE-2025-71359 picklescan CVE debrief
CVE-2025-71359 is a high-severity vulnerability in picklescan before version 0.0.29. The vulnerability allows remote code execution due to the failure of picklescan to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in the reduce method. Attackers can craft pickle files embedding dangerous code that evades picklescan detection and executes during pickle.load() deserialization. The vulnerability has a CVSS score of 7.6 and is considered high severity. The CVE was published on July 4, 2026.
- Vendor
- picklescan
- Product
- Unknown
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-04
- Original CVE updated
- 2026-07-04
- Advisory published
- 2026-07-04
- Advisory updated
- 2026-07-04
Who should care
Developers and users of picklescan before version 0.0.29 should be aware of this vulnerability. As the vendor and product information is not clearly identified, users of picklescan in general should take precautions. This vulnerability could allow attackers to execute remote code, potentially leading to system compromise.
Technical summary
The vulnerability exists in the picklescan library before version 0.0.29. Specifically, it fails to detect malicious pickle payloads that use the lib2to3.pgen2.grammar.Grammar.loads method in the reduce function. This allows attackers to craft malicious pickle files that can execute arbitrary code when deserialized using pickle.load(). The vulnerability is exacerbated by the fact that picklescan is designed to scan pickle files for malicious content, but in this case, it fails to identify dangerous payloads. The Common Weakness Enumeration (CWE) associated with this vulnerability is CWE-502, which involves the deserialization of untrusted data.
Defensive priority
High priority should be given to updating picklescan to version 0.0.29 or later. In the meantime, users should exercise caution when deserializing pickle files from untrusted sources.
Recommended defensive actions
- Update picklescan to version 0.0.29 or later.
- Validate and sanitize all pickle files before deserialization.
- Use secure protocols for transferring pickle files.
- Monitor systems for suspicious activity related to pickle file deserialization.
- Consider implementing additional security controls, such as using alternative serialization formats.
Evidence notes
The evidence for this CVE comes from the NVD and Vulncheck. The CVE was published on July 4, 2026. The vulnerability details were provided by Vulncheck, which identified the issue in picklescan. The CVE record and NVD detail pages provide additional context and technical information about the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-71359 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-71359
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-71359 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-71359
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/mmaitre314/picklescan/security/advisories/GHSA-f54q-57x4-jg88
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/picklescan-unsafe-deserialization-via-lib2to3-pgen2-grammar-grammar-loads
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.