CVE-2025-71321: picklescan - Arbitrary File Writing via distutils Module Bypass
picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.fileutil.writefile. Attackers can construct malicious pickle objects to overwrite critical system files and achieve denial of service or remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pypi/picklescanto a version that resolves this vulnerability.Fixed in 0.0.33
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71321?
CVE-2025-71321 has a severity rating of critical at 9.3.
How do I fix CVE-2025-71321?
To fix CVE-2025-71321, upgrade to picklescan version 0.0.33 or later.
What type of vulnerability is CVE-2025-71321?
CVE-2025-71321 is an arbitrary file writing vulnerability.
What impact can CVE-2025-71321 have on systems?
CVE-2025-71321 can allow attackers to overwrite critical system files, leading to denial of service or remote code execution.
Which software is affected by CVE-2025-71321?
CVE-2025-71321 affects picklescan versions before 0.0.33.