CVE-2025-10155 - CVE House
Back to Database
Status published Critical CVE-2025-10155

PickleScan Security Bypass Using Misleading File Extension

Vulnerability Description

An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the pickle file incorrectly considered safe is loaded, it can lead to the execution of malicious code.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-10155

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • JFrog
  • @xdcrev

Affected Vendor

Affected Software

picklescan
Vulnerable Versions:
0

Timeline

Official Publish: September 17th, 2025
Last Modified: September 17th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)