CVE-2025-10155
Severity CVSS v4.0:
CRITICAL
Type:
CWE-20
Input Validation
Publication date:
17/09/2025
Last modified:
02/10/2025
Description
An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the pickle file incorrectly considered safe is loaded, it can lead to the execution of malicious code.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:* | 0.0.31 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



