๐Ÿ” CVE Alert

CVE-2026-53875

UNKNOWN 0.0

picklescan - Scanning Bypass via Dynamic Eval in scan_pytorch

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to embed malicious magic numbers via dynamic eval using the __reduce__ trick. Attackers can craft malicious PyTorch payloads that evade picklescan detection while remaining executable, enabling arbitrary code execution when loaded with torch.load().

CWE CWE-95
Vendor picklescan
Product picklescan
Published Jun 17, 2026
Stay Ahead of the Next One

Get instant alerts for picklescan picklescan

Be the first to know when new unknown vulnerabilities affecting picklescan picklescan are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

picklescan / picklescan
0 < 1.0.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mmaitre314/picklescan/security/advisories/GHSA-97f8-7cmv-76j2 github.com: https://github.com/mmaitre314/picklescan/commit/2a8383cfeb4158567f9770d86597300c9e508d0f github.com: https://github.com/mmaitre314/picklescan/commit/134179474539648ba7dee1317959529fbd0e7f89 vulncheck.com: https://www.vulncheck.com/advisories/picklescan-scanning-bypass-via-dynamic-eval-in-scan-pytorch

Credits

๐Ÿ” zpbrent