CVE-2025-71320
picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using these unblocked functions to achieve arbitrary code execution when the pickle is deserialized.
- Affected products
- Picklescan
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.6% (46th percentile)
- Weakness
- CWE-184
- NVD status
- Deferred
- Published
- 2026-06-17
CVE-2025-71320 at NVD
No indexed exploits for CVE-2025-71320 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-71320 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.