CVE-2025-10155: MMAITRE314 Picklescan
High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.
An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the pickle file incorrectly considered safe is loaded, it can lead to the execution of malicious code.
Affected products
- MMAITRE314 Picklescan: before 0.0.31 (fixed in 0.0.31)
Published 2025-09-17. Last modified 2026-09-26.