Impact
Picklescan versions prior to 0.0.33 do not detect operator.methodcaller calls inside pickle files. An attacker can craft a malicious pickle payload that, when processed by the tool, triggers arbitrary code execution. The flaw is a failure to safeguard against unsafe data and maps to CWE‑693.
Affected Systems
Any deployment of the picklescan scanning tool that is running a version older than 0.0.33 is impacted. Systems that rely on picklescan to validate or load pickle data are impacted, as they may execute code from malformed or malicious files submitted by users or external parties.
Risk and Exploitability
The CVSS score of 7.6 indicates a high potential impact on confidentiality, integrity, and availability. A very low EPSS score (<1%) suggests that active exploitation is not widely observed, but the vulnerability remains exploitable by a remote attacker with the ability to deliver a crafted pickle file. The weakness is not listed in the CISA KEV catalog.
OpenCVE Enrichment