Back to Database
Status published
High
CVE-2025-71362
picklescan - Arbitrary Code Execution via Unsafe Deserialization in numpy.f2py.crackfortran
Vulnerability Description
picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbitrary strings. Attackers can embed malicious code in pickle files that executes when loaded from untrusted sources.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71362
Credits & Attribution
No credits recorded in the NVD database.
References
More from picklescan
View All →CVE-2025-71378
picklescan - Remote Code Execution via Undetected cProfile.runctx in Pickle Files
High
7.6
CVE-2025-71376
picklescan - Arbitrary Code Execution via Undetected idlelib.autocomplete.AutoComplete.fetch_completions
High
7.6
CVE-2025-71375
picklescan - Undetected Remote Code Execution via _operator.methodcaller
High
7.6
CVE-2025-71374
picklescan - Arbitrary Code Execution via Undetected profile.Profile.run
High
7.6
CVE-2025-71373
picklescan - Remote Code Execution via operator.methodcaller Detection Bypass
High
7.6
Affected Vendor
picklescan
View all reports →Affected Software
picklescan
Vulnerable Versions:
0, 0.0.33
Timeline
Official Publish:
July 4th, 2026
Last Modified:
July 6th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N