CVE-2025-71368
picklescan
picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files embedding doctest.debug_script calls that bypass picklescan detection and execute arbitrary commands upon pickle.load invocation.
- CVSS
- 7.6
- EPSS
- 0.77% 52.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.01