


Perceptive Security
SOC/SIEM Consultancy

Picklescan Bugs Allow Malicious PyTorch Models to Evade Scans and Execute Code
Published:
3 December 2025 at 09:30:00
Alert date:
5 December 2025 at 08:03:23
Source:
thehackernews.com

Three critical security flaws discovered in Picklescan, an open-source security scanner for Python pickle files. The vulnerabilities allow malicious actors to execute arbitrary code by loading untrusted PyTorch models while bypassing the tool's security protections. Picklescan is designed to parse Python pickle files and detect suspicious content, making these bypass vulnerabilities particularly concerning for organizations relying on the tool for security scanning of machine learning models.
Technical details
Mitigation steps:
Affected products:
Picklescan
PyTorch
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.