Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.getlincoef Gadget
Vulnerability Description
Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded, bypassing Picklescan's safety checks and enabling supply-chain poisoning of shared model files.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71372
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- ac0d3r
- Lyutoon
References
More from Picklescan
View All →Affected Vendor
Picklescan
View all reports →