


Perceptive Security
SOC/SIEM Consultancy

picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing atta…
Published:
3 juli 2026 om 22:00:00
Alert date:
4 juli 2026 om 03:05:56
Source:
nvd.nist.gov
Security Tools, Supply Chain & Dependencies, Zero-Day Vulnerabilities
CVE-2025-71369 affects picklescan versions before 0.0.28, a security tool used to detect malicious pickle files. The vulnerability allows attackers to bypass safety checks by using torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods within pickle files. Since picklescan fails to flag these files as malicious, embedded malicious code goes undetected. When the pickle file is deserialized by a target application, the malicious code executes, enabling remote code execution (RCE). This is particularly concerning in machine learning pipelines where pickle files are commonly used to share model weights and data. The fix was introduced in picklescan version 0.0.28. Users are strongly advised to upgrade to the patched version immediately. The issue was disclosed via GitHub Security Advisories and VulnCheck.
Technical details
Mitigation steps:
Affected products:
picklescan
PyTorch torch.utils.data.datapipes
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-71369
https://github.com/mmaitre314/picklescan/security/advisories/GHSA-h3qp-7fh3-f8h4
https://www.vulncheck.com/advisories/picklescan-unsafe-deserialization-via-torch-utils-data-datapipes-utils-decoder-basichandlers
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
