CVE-2025-71322 is a HIGH severity vulnerability in PickleScan before 0.0.33. The vulnerability allows attackers to bypass security checks and achieve arbitrary code execution when files are processed by PickleScan. Malicious actors can craft pickle payloads using the pty.spawn function to exploit this vulnerability. The vulnerability has a CVSS score of 8.7 and was published on June 17, 2026. The vendor, [truncated]
CVE-2025-71321 is a critical vulnerability in picklescan before version 0.0.33. The vulnerability allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file, enabling them to construct malicious pickle objects and overwrite critical system files. This can lead to denial of service or remote code execution. The vulnerability has a CVSS score of 9.3 and is considered critical [truncated]