CVE-2025-71375: Picklescan

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load().

Affected products

  • Picklescan Picklescan: before 0.0.34 (fixed in 0.0.34)

Published 2026-07-04. Last modified 2026-10-05.