CVE-2026-53875
picklescan
picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to embed malicious magic numbers via dynamic eval using the __reduce__ trick. Attackers can craft malicious PyTorch payloads that evade picklescan detection while remaining executable, enabling arbitrary code execution when loaded with torch.load().
- CVSS
- 7.1
- EPSS
- 0.43% 35.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.18