HomeSecurityVulnerabilities in Picklescan allow malicious PyTorch models to bypass checks

Vulnerabilities in Picklescan allow malicious PyTorch models to bypass checks

Three critical security vulnerabilities have been disclosed in an open-source tool called Picklescan, which could allow malicious actors to execute arbitrary code by loading untrusted PyTorch, effectively bypassing the tool's protections.

See also: OpenVPN: Vulnerabilities allow DoS and bypass of security mechanisms

Picklescan

Picklescan, developed and maintained by Matthieu Maitre, is a security scanner designed to analyze Python pickle files and detect suspicious inputs or function calls before they are executed. Pickle is a widely used serialization format in machine learning, including PyTorch, which uses the format to store and load models.

However, pickle files can pose significant security risks, as they can automatically cause arbitrary Python code to be executed when loaded. This makes it necessary for users and organizations to load trusted models from TensorFlow and Flax. The issues discovered by JFrog essentially make it possible to bypass the scanner, present the scanned model files as safe, and trigger the execution of malicious code, potentially paving the way for a supply chain attack.

Picklescan works by examining pickle files at the bytecode level and checking the results against a block list of known dangerous imports and functions to flag similar behavior. This approach, unlike whitelisting, means that it prevents the tool from detecting new attack vectors and requires developers to consider all potential malicious behavior.

See also: NVIDIA fixes critical vulnerabilities in DGX Spark 

Vulnerabilities in Picklescan allow malicious PyTorch models to bypass checks

The vulnerabilities are as follows:

– **CVE-2025-10155 (CVSS score: 9.3/7.8)**: A file extension bypass vulnerability that can compromise the scanner and load the model when a standard pickle file with a PyTorch-related extension, such as .bin or .pt, is provided.

– **CVE-2025-10156 (CVSS score: 9.3/7.5)**: An bypass vulnerability that can disable scanning of ZIP files by introducing a Cyclic Redundancy Check (CRC) error.

– **CVE-2025-10157 (CVSS score: 9.3/8.3)**: An override vulnerability that could undermine Picklescan's unsafe globals check, leading to arbitrary code execution by bypassing a blacklist of dangerous imports.

Successful exploitation of these flaws could allow attackers to hide malicious pickle payloads within files using common PyTorch extensions, intentionally introduce CRC errors into ZIP files containing malicious models, or create malicious PyTorch models with embedded pickle payloads to bypass the scanner.

See also: Vulnerability in Microsoft Update Health Tools configuration allows RCE

Vulnerabilities in Picklescan allow malicious PyTorch models to bypass checks

Following responsible disclosure on June 29, 2025, the three vulnerabilities have been addressed in version 0.0.31 of Picklescan released on September 9.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS