picklescan - Arbitrary Code Execution via Undetected ensurepip._run_pip Function
Vulnerability Description
picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function when scanning pickle files, allowing attackers to execute arbitrary code. Malicious pickle files embedding ensurepip._run_pip calls in __reduce__ methods bypass picklescan detection and achieve remote code execution upon pickle.load() invocation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71344
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- FredericDT
References
More from picklescan
View All →Affected Vendor
picklescan
View all reports →