Beveiligingsadvies

CVE-2026-53875

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-17 15:05:04
Laatst bijgewerkt 2026-06-17 17:50:32
Toegewezen door VulnCheck
CVSS-score 7.1
Status PUBLISHED

Beschrijving

picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to embed malicious magic numbers via dynamic eval using the __reduce__ trick. Attackers can craft malicious PyTorch payloads that evade picklescan detection while remaining executable, enabling arbitrary code execution when loaded with torch.load().