CRITICAL10.0CVE-2026-3490PickleScan's pkgutil.resolve_name has a universal blocklist bypass from 0, < 1.0.4
CRITICAL9.8CVE-2026-56315PickleScan has multiple stdlib modules with direct RCE not in blocklist from 0, < 1.0.4
CRITICAL9.8CVE-2026-53873PickleScan's profile.run blocklist mismatch allows exec() bypass from 0, < 1.0.4
CRITICAL9.8Picklescan does not block ctypes
from 0, < 0.0.33
CRITICAL9.8Picklescan does not block ctypes
from 0, < 0.0.33
CRITICAL9.8Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
from 0, < 0.0.23
CRITICAL9.8Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
from 0, < e58e45e0d9e091159c1554f9b04828bbb40b9781 | from 0, < 0.0.23
CRITICAL9.8PyTorch Model Files Can Bypass Pickle Scanners via Unexpected Pickle Extensions
from 0, < 0.0.22
HIGH8.8Picklescan Bypasses Unsafe Globals Check using pty.spawn
from 0, < 0.0.33
HIGH8.8Picklescan Bypasses Unsafe Globals Check using pty.spawn
from 0, < 0.0.33
HIGH8.3Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports
from 0, < 0.0.31
HIGH8.3Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports
from 0, < 0.0.31
HIGH8.1Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
from 0, < 0.0.33
HIGH8.1Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip
from 0, < 0.0.29
HIGH8.1Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity
from 0, < 0.0.29
HIGH7.8Picklescan Bypass is Possible via File Extension Mismatch
from 0, < 0.0.31
HIGH7.8Picklescan Bypass is Possible via File Extension Mismatch
from 0, < 0.0.31
HIGH7.8Picklescan is missing detection when calling built-in python cProfile.runctx
from 0, < 0.0.30
HIGH7.8Picklescan is missing detection when calling built-in python cProfile.runctx
from 0, < 0.0.30
HIGH7.8Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
from 0, < 0.0.30
HIGH7.8Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand
from 0, < 0.0.30
HIGH7.8Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
from 0, < 0.0.28
HIGH7.8Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
from 0, < 0.0.28
HIGH7.5picklescan has Arbitrary file read using `io.FileIO`
from 0, < 0.0.35
HIGH7.5picklescan has Arbitrary file read using `io.FileIO`
from 0, < 0.0.35
HIGH7.5Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check
from 0, < 0.0.31
HIGH7.5Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check
from 0, < 0.0.31
MEDIUM6.5Zip Exploit Crashes Picklescan But Not PyTorch
from 0, < 0.0.23
MEDIUM6.5Zip Exploit Crashes Picklescan But Not PyTorch
from 0, < e58e45e0d9e091159c1554f9b04828bbb40b9781 | from 0, < 0.0.23
—Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
from 0, < 1.0.3
—Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
from 0, < 1.0.3
—picklescan vulnerable to arbitrary file create using logging.FileHandler
from 0, < 1.0.1
—picklescan vulnerable to arbitrary file create using logging.FileHandler
from 0, < 1.0.1
—picklescan missing detection by simple obfuscation of a `builtins.eval` call
from 0, < 1.0.1
—picklescan missing detection by simple obfuscation of a `builtins.eval` call
from 0, < 1.0.1
—Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter
from 0, < 0.0.34
—Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller
from 0, < 0.0.34
—Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef
from 0, < 0.0.33
—Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval
from 0, < 0.0.33
—Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
from 0, < 0.0.33
—Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller
from 0, < 0.0.33
—Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef
from 0, < 0.0.33
—Picklescan has Incomplete List of Disallowed Inputs
from 0, < 0.0.33
—Picklescan has Incomplete List of Disallowed Inputs
from 0, < 0.0.33
—Picklescan vulnerable to Arbitrary File Writing
from 0, < 0.0.33
—Picklescan vulnerable to Arbitrary File Writing
from 0, < 0.0.33
—Picklescan is missing detection when calling built-in python library asyncio.unix_events._UnixSubprocessTransport._start
from 0, < 0.0.30
—Picklescan is missing detection when calling built-in python cProfile.run
from 0, < 0.0.30
—Picklescan is missing detection when calling built-in python doctest.debug_script
from 0, < 0.0.30
—Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode
from 0, < 0.0.30
—Picklescan is missing detection when calling built-in python idlelib.run.Executive.runcode
from 0, < 0.0.30
—Picklescan is missing detection when calling built-in python lib2to3.pgen2.pgen.ParserGenerator.make_label
from 0, < 0.0.30
—Picklescan is missing detection when calling built-in python ensurepip._run_pip
from 0, < 0.0.30
—Picklescan is missing detection when calling built-in python ensurepip._run_pip
from 0, < 0.0.30
—Picklescan is missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_autograd_prof
from 0, < 0.0.30
—Picklescan has a missing detection when calling built-in python library idlelib.calltip.get_entity
from 0, < 0.0.29
—Picklescan has a missing detection when calling built-in python code.InteractiveInterpreter
from 0, < 0.0.29
—Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions
from 0, < 0.0.29
—Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem
from 0, < 0.0.29
—Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem
from 0, < 0.0.29
—Picklescan has a missing detection when calling built-in python lib2to3.pgen2.grammar.Grammar.loads
from 0, < 0.0.29
—Picklescan has a missing detection when calling built-in python profile.Profile.runctx
from 0, < 0.0.29
—Picklescan has a missing detection when calling built-in python profile.Profile.run
from 0, < 0.0.29
—Picklescan has a missing detection when calling built-in python trace.Trace.runctx
from 0, < 0.0.29
—Picklescan has a missing detection when calling built-in python trace.Trace.run
from 0, < 0.0.29
—Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
from 0, < 0.0.28
—Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
from 0, < 0.0.28
—Picklescan missing detection when calling pytorch function torch.utils.data.datapipes.utils.decoder.basichandlers
from 0, < 0.0.28
—Picklescan missing detection when calling pytorch function torch.utils.collect_env.run
from 0, < 0.0.28
—Picklescan missing detection when calling pytorch function torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression
from 0, < 0.0.28
—Picklescan missing detection when calling pytorch function torch._dynamo.guards.GuardBuilder.get
from 0, < 0.0.28
—Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile
from 0, < 0.0.28
—Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
from 0, < 0.0.27
—Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass
from 0, < 0.0.27
—Picklescan missing detection when calling built-in python library function timeit.timeit()
from 0, < 0.0.25
—Picklescan failed to detect to some unsafe global function in Numpy library
from 0, < 0.0.25
—Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
from 0, < 0.0.25