Security Advisory

CVE-2025-71375

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-04 01:23:42
Last updated 2026-07-07 16:58:14
Assigner VulnCheck
CVSS score 7.6
State PUBLISHED

Description

picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load().