CVE-2025-71339: Picklescan

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded by victims who trust Picklescan's safety validation.

Affected products

  • Picklescan Picklescan: before 0.0.33 (fixed in 0.0.33)

Published 2026-06-22. Last modified 2026-10-05.