CVE-2025-71361: picklescan - Remote Code Execution via Undetected idlelib.calltip.Calltip.fetch_tip
Published Jun 24, 2026
·Updated
picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetchtip calls in pickle files, allowing remote code execution. Attackers can embed undetected payloads in pickle files that execute arbitrary code when loaded via pickle.load().
Affected Software
1 affected component
pypi/picklescan<0.0.29
Event History
Jun 24, 2026
CVE Published
via MITRE·11:53 AM
Data Sourced
via MITRE·11:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-71361?
CVE-2025-71361 has a severity rating of 8.1, classified as high.
2
How do I fix CVE-2025-71361?
To address CVE-2025-71361, upgrade picklescan to version 0.0.29 or later.
3
What kind of vulnerability is CVE-2025-71361?
CVE-2025-71361 is a Remote Code Execution vulnerability linked to malicious calls in pickle files.
4
What can an attacker achieve with CVE-2025-71361?
An attacker can execute arbitrary code on a victim's machine by embedding malicious payloads in pickle files.
5
Which software is affected by CVE-2025-71361?
CVE-2025-71361 affects picklescan versions prior to 0.0.29.