Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

picklescan — Vulnerabilities & Security Advisories 58

All 58 CVE vulnerabilities found in picklescan, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page focuses on PickleScan, a static analysis tool designed for detecting vulnerabilities in Solidity smart contracts. The page collects publicly disclosed security advisories, bug reports, and known weaknesses specifically impacting the PickleScan product and its associated tooling. It covers the historical record of identified defects, spanning from the tool’s initial release through the latest available data. Readers can track the vendor’s advisory timeline, analyze the frequency of specific weakness classes, and review the complete vulnerability history of the product. The data is organized to highlight recurring patterns, such as logic errors in contract verification modules or issues in the scanner’s core analysis engine. Each entry links to the original source, ensuring transparency and traceability. This view is intended for security engineers, smart contract auditors, and developers who rely on PickleScan and need to understand its reliability and known limitations. By aggregating these records, the page provides a centralized reference for assessing the tool’s security posture and the nature of defects discovered in its operation. Users can filter entries by weakness type or date range to isolate specific issues relevant to their audit workflows.

Vendor: mmaitre314

CVE ID Title CVSS Severity Published
CVE-2025-71375 picklescan - Undetected Remote Code Execution via _operator.methodcaller CWE-502 8.1 High 2026-07-04
CVE-2025-71372 Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.getlincoef Gadget CWE-502 8.1 High 2026-07-04
CVE-2025-71373 picklescan - Remote Code Execution via operator.methodcaller Detection Bypass CWE-693 8.1 High 2026-07-04
CVE-2025-71369 picklescan - Unsafe Deserialization via torch.utils.data.datapipes.utils.decoder.basichandlers CWE-502 8.1 High 2026-07-04
CVE-2025-71367 picklescan - Remote Code Execution via _operator.attrgetter Detection Bypass CWE-502 8.1 High 2026-07-04
CVE-2025-71366 picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_cprofile CWE-502 8.1 High 2026-07-04
CVE-2025-71364 picklescan - Arbitrary Code Execution via Undetected asyncio.unix_events._UnixSubprocessTransport._start CWE-502 8.1 High 2026-07-04
CVE-2025-71360 picklescan - Remote Code Execution via Undetected idlelib.calltip.get_entity CWE-502 8.1 High 2026-07-04
CVE-2025-71362 picklescan - Arbitrary Code Execution via Unsafe Deserialization in numpy.f2py.crackfortran CWE-502 8.1 High 2026-07-04
CVE-2025-71359 picklescan - Unsafe Deserialization via lib2to3.pgen2.grammar.Grammar.loads CWE-502 8.1 High 2026-07-04
CVE-2025-71356 picklescan - Arbitrary Code Execution via torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression CWE-502 8.1 High 2026-07-04
CVE-2025-71353 picklescan - Remote Code Execution via torch._dynamo.guards.GuardBuilder.get CWE-502 8.1 High 2026-07-04
CVE-2025-71347 picklescan - Undetected Remote Code Execution via numpy.f2py.crackfortran.param_eval CWE-502 8.1 High 2026-07-04
CVE-2025-71345 picklescan - Arbitrary Code Execution via torch.utils.bottleneck.__main__.run_autograd_prof CWE-502 8.1 High 2026-07-04
CVE-2025-71342 picklescan - Undetected Remote Code Execution via idlelib.run.Executive.runcode CWE-502 8.1 High 2026-07-04
CVE-2025-71343 picklescan - Arbitrary Code Execution via lib2to3.pgen2.pgen.ParserGenerator.make_label Detection Bypass CWE-502 8.1 High 2026-07-04
CVE-2025-71374 picklescan - Arbitrary Code Execution via Undetected profile.Profile.run CWE-502 8.1 High 2026-06-30
CVE-2025-71371 picklescan - Remote Code Execution via code.InteractiveInterpreter Detection Bypass CWE-502 8.1 High 2026-06-30
CVE-2025-71368 picklescan - Arbitrary Code Execution via Undetected doctest.debug_script CWE-502 8.1 High 2026-06-30
CVE-2025-71363 picklescan - Arbitrary Code Execution via Undetected cProfile.run in Pickle Deserialization CWE-502 8.1 High 2026-06-30
CVE-2025-71355 Picklescan - Arbitrary Code Execution via Unsafe Numpy Function Detection Bypass CWE-184 - - 2026-06-30
CVE-2025-71350 picklescan - Undetected Remote Code Execution via torch.utils.collect_env.run CWE-502 8.1 High 2026-06-30
CVE-2025-71352 picklescan - Remote Code Execution via Undetected trace.Trace.runctx in Pickle Files CWE-693 8.1 High 2026-06-30
CVE-2025-71349 picklescan - Arbitrary Code Execution via Undetected trace.Trace.run in Pickle Files CWE-502 8.1 High 2026-06-30
CVE-2025-71340 picklescan - Remote Code Execution via idlelib.pyshell.ModifiedInterpreter.runcode CWE-502 8.1 High 2026-06-25
CVE-2025-71361 picklescan - Remote Code Execution via Undetected idlelib.calltip.Calltip.fetch_tip CWE-95 8.1 High 2026-06-24
CVE-2025-71354 picklescan - Remote Code Execution via idlelib.debugobj.ObjectTreeItem.SetText CWE-502 8.1 High 2026-06-24
CVE-2026-56315 picklescan - Remote Code Execution via Unblocked Standard Library Modules CWE-184 9.8 Critical 2026-06-23
CVE-2025-71376 picklescan - Arbitrary Code Execution via Undetected idlelib.autocomplete.AutoComplete.fetch_completions CWE-502 8.1 High 2026-06-23
CVE-2025-71370 picklescan - Remote Code Execution via torch.jit.unsupported_tensor_ops.execWrapper CWE-502 8.1 High 2026-06-23

All 58 known CVE vulnerabilities affecting picklescan with full Chinese analysis, references, and POCs where available.