CVE-2026-3490: Picklescan

Critical severity, CVSS 10.0. EPSS: 0.9% chance of exploitation in the next 30 days.

picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function through indirect REDUCE calls. Remote attackers can invoke any blocked function such as os.system, builtins.exec, or subprocess.call to achieve remote code execution.

Affected products

  • Picklescan Picklescan: before 1.0.4 (fixed in 1.0.4)

Published 2026-06-17. Last modified 2026-06-18.