top of page
perceptive_background_267k.jpg

Picklescan Bugs Allow Malicious PyTorch Models to Evade Scans and Execute Code

Published:

3 december 2025 om 09:30:00

Alert date:

5 december 2025 om 08:03:23

Source:

thehackernews.com

Click to open the original link from this advisory

Three critical security flaws discovered in Picklescan, an open-source security scanner for Python pickle files. The vulnerabilities allow malicious actors to execute arbitrary code by loading untrusted PyTorch models while bypassing the tool's security protections. Picklescan is designed to parse Python pickle files and detect suspicious content, making these bypass vulnerabilities particularly concerning for organizations relying on the tool for security scanning of machine learning models.

Technical details

Mitigation steps:

Affected products:

Picklescan
PyTorch

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page