Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

picklescan — Vulnerabilities & Security Advisories 58

All 58 CVE vulnerabilities found in picklescan, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page focuses on PickleScan, a static analysis tool designed for detecting vulnerabilities in Solidity smart contracts. The page collects publicly disclosed security advisories, bug reports, and known weaknesses specifically impacting the PickleScan product and its associated tooling. It covers the historical record of identified defects, spanning from the tool’s initial release through the latest available data. Readers can track the vendor’s advisory timeline, analyze the frequency of specific weakness classes, and review the complete vulnerability history of the product. The data is organized to highlight recurring patterns, such as logic errors in contract verification modules or issues in the scanner’s core analysis engine. Each entry links to the original source, ensuring transparency and traceability. This view is intended for security engineers, smart contract auditors, and developers who rely on PickleScan and need to understand its reliability and known limitations. By aggregating these records, the page provides a centralized reference for assessing the tool’s security posture and the nature of defects discovered in its operation. Users can filter entries by weakness type or date range to isolate specific issues relevant to their audit workflows.

Vendor: mmaitre314

CVE ID Title CVSS Severity Published
CVE-2025-71365 picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.myeval Detection Bypass CWE-502 8.1 High 2026-06-23
CVE-2025-71341 picklescan - Remote Code Execution via Undetected profile.Profile.runctx CWE-502 8.1 High 2026-06-23
CVE-2025-71358 picklescan - Remote Code Execution via idlelib.autocomplete.AutoComplete.get_entity CWE-502 8.1 High 2026-06-22
CVE-2025-71344 picklescan - Arbitrary Code Execution via Undetected ensurepip._run_pip Function CWE-502 8.1 High 2026-06-22
CVE-2025-71339 Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran._eval_length Gadget CWE-502 8.1 High 2026-06-22
CVE-2025-71378 picklescan - Remote Code Execution via Undetected cProfile.runctx in Pickle Files CWE-502 8.1 High 2026-06-21
CVE-2025-71351 picklescan - Remote Code Execution via timeit.timeit() Detection Bypass CWE-184 - - 2026-06-21
CVE-2025-71357 picklescan - Arbitrary Code Execution via Undetected idlelib.pyshell.ModifiedInterpreter.runcommand CWE-502 8.1 High 2026-06-21
CVE-2025-71348 picklescan - Arbitrary Code Execution via torch.utils._config_module.load_config Bypass CWE-502 8.1 High 2026-06-21
CVE-2026-56304 picklescan - Arbitrary File Creation via logging.FileHandler Deserialization CWE-502 6.5 Medium 2026-06-20
CVE-2026-53874 picklescan - Arbitrary Code Execution via Obfuscated eval Call CWE-502 9.8 Critical 2026-06-17
CVE-2026-53875 picklescan - Scanning Bypass via Dynamic Eval in scan_pytorch CWE-95 - - 2026-06-17
CVE-2026-53873 picklescan - Arbitrary Code Execution via profile.run() Blocklist Bypass CWE-184 9.8 Critical 2026-06-17
CVE-2026-3490 picklescan - Universal Blocklist Bypass via pkgutil.resolve_name CWE-183 10.0 Critical 2026-06-17
CVE-2026-53872 picklescan - Arbitrary File Read via Unsafe Pickle Deserialization CWE-22 7.5 High 2026-06-17
CVE-2025-71325 picklescan - Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw CWE-391 9.8 Critical 2026-06-17
CVE-2025-71323 picklescan - Remote Code Execution via Unblocked ctypes Module CWE-184 9.8 Critical 2026-06-17
CVE-2025-71322 PickleScan - Unsafe Globals Check Bypass via pty.spawn Function CWE-693 8.8 High 2026-06-17
CVE-2025-71321 picklescan - Arbitrary File Writing via distutils Module Bypass CWE-502 9.8 Critical 2026-06-17
CVE-2025-71320 picklescan - Remote Code Execution via Incomplete Disallowed Inputs CWE-184 9.8 Critical 2026-06-17
CVE-2025-10157 PickleScan Bypasses Unsafe Globals Check Using Submodule Imports CWE-693 9.8AI Critical AI 2025-09-17
CVE-2025-10156 PickleScan Security Bypass via Bad CRC in ZIP Archive CWE-755 7.8AI High AI 2025-09-17
CVE-2025-10155 PickleScan Security Bypass Using Misleading File Extension CWE-20 9.8AI Critical AI 2025-09-17
CVE-2025-46417 picklescan 安全漏洞 CWE-184 9.1 - 2025-04-24
CVE-2025-1945 picklescan - Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch CWE-345 9.8 - 2025-03-10
CVE-2025-1944 picklescan ZIP archive manipulation attack leads to crash CWE-345 7.5 - 2025-03-10
CVE-2025-1889 picklescan - Security scanning bypass via non-standard file extensions CWE-646 7.5 - 2025-03-03
CVE-2025-1716 picklescan - Security scanning bypass via 'pip main' CWE-184 8.1 - 2025-02-26

All 58 known CVE vulnerabilities affecting picklescan with full Chinese analysis, references, and POCs where available.