CVE-2025-71352
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-693
Fallo del mecanismo de protección
Fecha de publicación:
30/06/2026
Última modificación:
01/07/2026
Descripción
*** Pendiente de traducción *** picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files with trace.Trace.runctx payloads that bypass picklescan detection and execute code upon pickle.load() invocation.
Impacto
Puntuación base 4.0
7.60
Gravedad 4.0
ALTA
Puntuación base 3.x
8.10
Gravedad 3.x
ALTA



