CVE-2025-71357
🟠 Łataj w tym tygodniu
Błąd w PickleScan umożliwia atakującym osadzanie złośliwego kodu w plikach pickle.
CVSS
8.1
EPSS
0.4%
Exploit
poc
Vendor
mmaitre314
Opis źródłowy (NVD)
picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-06-21 14:16:23 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-05 16:10:00 UTC |
Referencje
- https://github.com/mmaitre314/picklescan/security/advisories/GHSA-j343-8v2j-ff7w ([email protected]) [Exploit, Vendor Advisory]
- https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-undetected-idlelib-pyshell-modifiedinterpreter-runcommand ([email protected]) [Third Party Advisory]