Picklescan
AI Threat Alert tracks 15 known AI/ML vulnerabilities affecting Picklescan products — each enriched with CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis. Browse every Picklescan CVE below, sorted by severity and recency.
| Severity | CVE | Headline | Package | CVSS |
|---|---|---|---|---|
| CRITICAL | CVE-2025-71321 | picklescan: blocklist bypass allows arbitrary file write/RCE | picklescan | 9.8 |
| CRITICAL | CVE-2025-71320 | picklescan: deny-list bypass enables arbitrary RCE | picklescan | 9.8 |
| CRITICAL | CVE-2025-71323 | picklescan: ctypes bypass enables full RCE via pickle files | picklescan | 9.8 |
| CRITICAL | CVE-2025-71325 | picklescan: scanner bypass enables RCE via model files | picklescan | 9.8 |
| HIGH | CVE-2025-71322 | PickleScan: pty.spawn bypass enables RCE in model scans | PickleScan | 8.8 |
| CRITICAL | CVE-2026-3490 | picklescan: blocklist bypass enables full RCE | picklescan | 10.0 |
| HIGH | CVE-2026-53872 | picklescan: arbitrary file read bypasses RCE blocklist | picklescan | 7.5 |
| CRITICAL | CVE-2026-53874 | picklescan: scanner bypass enables pickle RCE | picklescan | 9.8 |
| CRITICAL | CVE-2026-53873 | picklescan: blocklist bypass allows arbitrary code exec | picklescan | 9.8 |
| HIGH | CVE-2025-71348 | picklescan: scanner bypass enables supply chain RCE | picklescan | 8.1 |
| HIGH | CVE-2025-71378 | picklescan: detection bypass enables RCE via pickle files | picklescan | 8.1 |
| HIGH | CVE-2025-71357 | picklescan: detection bypass enables RCE via malicious models | picklescan | 8.1 |
| HIGH | CVE-2025-71351 | picklescan: scanner bypass enables RCE via pickle files | picklescan | - |
| HIGH | CVE-2025-71354 | picklescan: scanner bypass enables arbitrary code execution | picklescan | 8.1 |
| HIGH | CVE-2025-71361 | picklescan: scanner bypass allows RCE via pickle load | picklescan | 8.1 |
Frequently asked questions
How many known vulnerabilities affect Picklescan?
15 AI/ML CVEs affecting Picklescan products are tracked, sourced from NVD and GitHub Advisory.
What Picklescan products are affected?
The CVEs below map to the Picklescan AI/ML packages and tools tracked by AI Threat Alert; open any CVE to see the affected components and versions.
Where does the Picklescan vulnerability data come from?
Data is sourced from NVD and GitHub Advisory, then enriched with CVSS severity, EPSS exploit probability, and patch status for each CVE.
How can I monitor Picklescan for new vulnerabilities?
AI Threat Alert tracks Picklescan continuously; a Pro subscription adds breaking alerts when new CVEs affecting Picklescan are published.
How do I assess Picklescan's security exposure?
Each CVE below carries CVSS severity and exploitation signals, so you can review the highest-severity Picklescan issues first and judge the exposure for your stack.