


Perceptive Security
SOC/SIEM Consultancy

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attacker…
Published:
3 juli 2026 om 22:00:00
Alert date:
4 juli 2026 om 03:05:56
Source:
nvd.nist.gov
Supply Chain & Dependencies, Security Tools, Emerging Technologies
CVE-2025-71372 affects Picklescan versions before 0.0.33, a security tool designed to detect malicious pickle files. The vulnerability stems from Picklescan's failure to detect the numpy.f2py.crackfortran.getlincoef gadget used in pickle __reduce__ methods. Attackers can craft malicious pickle files that execute arbitrary Python code upon loading, effectively bypassing Picklescan's safety checks. This flaw poses a significant supply-chain risk, as shared machine learning model files distributed in pickle format could be poisoned. The attack vector is particularly dangerous in AI/ML ecosystems where model sharing is common. A fix was introduced in Picklescan version 0.0.33. Users and organizations relying on Picklescan for model security validation should update immediately. The vulnerability has been publicly disclosed with supporting advisories from GitHub and VulnCheck.
Technical details
Mitigation steps:
Affected products:
Picklescan
numpy
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-71372
https://github.com/mmaitre314/picklescan/security/advisories/GHSA-rrxm-2pvv-m66x
https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-numpy-f2py-crackfortran-getlincoef-gadget
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
