CVE-2025-71350: picklescan - Undetected Remote Code Execution via torch.utils.collect_env.run
Published Jun 30, 2026
·Updated
picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collectenv.run function in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.
Affected Software
1 affected component
picklescan<0.0.28
Event History
Jun 30, 2026
CVE Published
via MITRE·10:08 PM
Data Sourced
via MITRE·10:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Jan 20, 58467
Event
via NVD·03:46 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-71350?
The severity of CVE-2025-71350 is high, with a score of 7.6.
2
How do I fix CVE-2025-71350?
To fix CVE-2025-71350, upgrade picklescan to version 0.0.28 or later.
3
What type of vulnerability is CVE-2025-71350?
CVE-2025-71350 is a remote code execution vulnerability.
4
What is affected by CVE-2025-71350?
CVE-2025-71350 affects versions of picklescan prior to 0.0.28.
5
Can CVE-2025-71350 lead to data compromise?
Yes, CVE-2025-71350 can lead to data compromise due to undetected malicious code execution.