Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran._eval_length Gadget
Vulnerability Description
Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded by victims who trust Picklescan's safety validation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71339
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- ac0d3r
- Lyutoon
References
More from Picklescan
View All →Affected Vendor
Picklescan
View all reports →