CVE-2025-71342: picklescan - Undetected Remote Code Execution via idlelib.run.Executive.runcode

Published Jul 4, 2026
·
Updated

picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in PyTorch models and supply chain attacks.

Affected Software

1 affected component
picklescan<0.0.30

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade picklescan to a version that resolves this vulnerability.

    Fixed in 0.0.30
  2. Compensating control

    Use picklescan version 0.0.30 or later to scan pickle files for undetected remote code execution via idlelib.run.Executive.runcode in reduce methods.

Event History

Jul 4, 2026
CVE Published
via MITRE·01:23 AM
Data Sourced
via MITRE·01:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-71342?

CVE-2025-71342 has a high severity score of 8.1.

2

How do I fix CVE-2025-71342?

To mitigate CVE-2025-71342, upgrade picklescan to version 0.0.30 or later.

3

What is the impact of CVE-2025-71342 on my system?

CVE-2025-71342 allows attackers to execute remote code through malicious pickle files, posing a significant security risk.

4

Which software is affected by CVE-2025-71342?

CVE-2025-71342 affects picklescan versions prior to 0.0.30.

5

What type of attack does CVE-2025-71342 enable?

CVE-2025-71342 can enable remote code execution and supply chain attacks through undetected malicious code in pickle files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203