CVE-2025-71371: Picklescan

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce methods. Attackers can craft pickle payloads that bypass picklescan detection and execute arbitrary code when loaded via pickle.load().

Affected products

  • Picklescan Picklescan: before 0.0.29 (fixed in 0.0.29)

Published 2026-06-30. Last modified 2026-10-05.