Sploitus

CVE-2025-10157

No indexed exploits for CVE-2025-10157 yet

A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check. This is possible because the scanner performs an exact match for module names, allowing malicious payloads to be loaded via submodules of dangerous packages (e.g., 'asyncio.unix_events' instead of 'asyncio'). When the incorrectly considered safe file is loaded after scan, it can lead to the execution of malicious code.

Affected products
Picklescan
mmaitre314 Picklescan
< 0.0.31
Fix
Available
CVSS 4.0
9.3 CRITICAL
CVSS 3.1
7.8 HIGH
EPSS
0.8% (52th percentile)
Weakness
CWE-693
NVD status
Analyzed
Published
2025-09-17
CVE-2025-10157 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-10157 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-10157 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.