CVE-2025-71362: picklescan - Arbitrary Code Execution via Unsafe Deserialization in numpy.f2py.crackfortran
Published Jul 4, 2026
·Updated
picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. Attackers can embed malicious code in pickle files that executes when loaded from untrusted sources.
Affected Software
1 affected component
picklescan<0.0.33
Event History
Jul 4, 2026
CVE Published
via MITRE·01:23 AM
Data Sourced
via MITRE·01:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-71362?
CVE-2025-71362 has a severity rating of 8.1, classified as high.
2
How do I fix CVE-2025-71362?
To fix CVE-2025-71362, upgrade picklescan to version 0.0.33 or later.
3
What type of vulnerability is CVE-2025-71362?
CVE-2025-71362 is an arbitrary code execution vulnerability caused by unsafe deserialization.
4
What are the consequences of CVE-2025-71362?
Exploitation of CVE-2025-71362 can allow attackers to execute arbitrary code through malicious pickle files.
5
Who is affected by CVE-2025-71362?
CVE-2025-71362 affects users of picklescan versions prior to 0.0.33 using numpy.f2py.crackfortran.