LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2025-71320

Published
CVSS9.8
Severitycritical
WeaknessCWE-184
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using these unblocked functions to achieve arbitrary code execution when the pickle is deserialized.

References

← Back to the CVE Tracker

Our coverage of CVE-2025-71320

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-71320.