CVE-2025-71366: picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_cprofile
Published Jul 4, 2026
·Updated
picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.main.runcprofile function calls in pickle files, allowing attackers to bypass safety checks. Remote attackers can embed undetected code in pickle files to achieve arbitrary code execution when victims load the files.
Affected Software
1 affected component
pypi/picklescan<0.0.28
Event History
Jul 4, 2026
CVE Published
via MITRE·01:23 AM
Data Sourced
via MITRE·01:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-71366?
The severity of CVE-2025-71366 is high with a score of 8.1.
2
How do I fix CVE-2025-71366?
To fix CVE-2025-71366, upgrade to picklescan version 0.0.28 or later.
3
What type of vulnerability is CVE-2025-71366?
CVE-2025-71366 is an Arbitrary Code Execution vulnerability.
4
What impact does CVE-2025-71366 have on users?
CVE-2025-71366 allows remote attackers to execute arbitrary code by embedding malicious functions in pickle files.
5
What software is affected by CVE-2025-71366?
CVE-2025-71366 affects the picklescan software prior to version 0.0.28.