PickleScan - Unsafe Globals Check Bypass via pty.spawn Function
Vulnerability Description
PickleScan before 0.0.33 fails to include the pty.spawn function in its unsafe globals list, allowing attackers to bypass security checks. Malicious actors can craft pickle payloads using pty.spawn to achieve arbitrary code execution when files are processed by PickleScan.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71322
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- yarienkiva
Affected Vendor
PickleScan
View all reports →