CVE-2025-71348
Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
7.8
HIGH
CVSS 3.1
EPSS 0.40%
Description
picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply chain attacks.
How to fix CVE-2025-71348
To remediate CVE-2025-71348, upgrade the affected package to a fixed version below.
- —upgrade to 0.0.28 or later
- —upgrade to 0.0.28 or later
Is CVE-2025-71348 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.0.28
- from 0, < 0.0.28
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |