Vulnerability Description
An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the pickle file incorrectly considered safe is loaded, it can lead to the execution of malicious code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mmaitre314 | Picklescan | < 0.0.31 |
Related Weaknesses (CWE)
References
- https://github.com/mmaitre314/picklescan/blob/58983e1c20973ac42f2df7ff15d7c8cd32Product
- https://github.com/mmaitre314/picklescan/security/advisories/GHSA-jgw4-cr84-mqxgExploitPatchVendor Advisory
FAQ
What is CVE-2025-10155?
CVE-2025-10155 is a vulnerability with a CVSS score of 7.8 (HIGH). An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplyi...
How severe is CVE-2025-10155?
CVE-2025-10155 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-10155?
Check the references section above for vendor advisories and patch information. Affected products include: Mmaitre314 Picklescan.