CVE-2025-71375: picklescan - Undetected Remote Code Execution via _operator.methodcaller
Published Jul 4, 2026
·Updated
picklescan before 0.0.34 fails to detect the operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load().
Affected Software
1 affected component
pypi/picklescan<0.0.34
Event History
Jul 4, 2026
CVE Published
via MITRE·01:23 AM
Data Sourced
via MITRE·01:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Apr 28, 58475
Event
via NVD·08:50 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-71375?
The severity of CVE-2025-71375 is rated as high with a score of 8.1.
2
How do I fix CVE-2025-71375?
To fix CVE-2025-71375, update picklescan to version 0.0.34 or later.
3
What is the risk associated with CVE-2025-71375?
CVE-2025-71375 has a risk score of 59, indicating significant potential threats.
4
What type of vulnerability is CVE-2025-71375?
CVE-2025-71375 is classified as an undetected remote code execution vulnerability.
5
Which software is affected by CVE-2025-71375?
The affected software by CVE-2025-71375 is picklescan prior to version 0.0.34.