picklescan - Undetected Remote Code Execution via _operator.methodcaller
Vulnerability Description
picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load().
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71375
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- CoolwindHF
References
More from picklescan
View All →Affected Vendor
picklescan
View all reports →