picklescan ZIP archive manipulation attack leads to crash
Vulnerability Description
picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model archives. By modifying the filename in the ZIP header while keeping the original filename in the directory listing, an attacker can make PickleScan raise a BadZipFile error. However, PyTorch's more forgiving ZIP implementation still allows the model to be loaded, enabling malicious payloads to bypass detection.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1944
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Trevor Madge (@madgetr) of Sonatype
References
More from mmaitre314
View All →Affected Vendor
mmaitre314
View all reports →