CVE-2025-71371: picklescan - Remote Code Execution via code.InteractiveInterpreter Detection Bypass
Published Jun 30, 2026
·Updated
picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce methods. Attackers can craft pickle payloads that bypass picklescan detection and execute arbitrary code when loaded via pickle.load().
Affected Software
1 affected component
pypi/picklescan<0.0.29
Event History
Jun 30, 2026
CVE Published
via MITRE·10:08 PM
Data Sourced
via MITRE·10:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-71371?
The severity of CVE-2025-71371 is high, rated at 7.6 on the CVSS scale.
2
How do I fix CVE-2025-71371?
To fix CVE-2025-71371, upgrade picklescan to version 0.0.29 or later.
3
What type of vulnerability is identified by CVE-2025-71371?
CVE-2025-71371 is a remote code execution vulnerability due to detection bypass in picklescan.
4
What can attackers achieve with CVE-2025-71371?
Attackers can execute arbitrary code by crafting malicious pickle files that bypass picklescan detection.
5
Which software is affected by CVE-2025-71371?
CVE-2025-71371 affects versions of picklescan prior to 0.0.29.