Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3vg9-h568-4w9m | Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 24 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Picklescan
Picklescan picklescan |
|
| Vendors & Products |
Picklescan
Picklescan picklescan |
Wed, 24 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Jun 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in reduce methods. Attackers can craft pickle files with embedded code that bypasses picklescan detection and executes arbitrary commands when pickle.load() is called. | |
| Title | picklescan - Remote Code Execution via idlelib.debugobj.ObjectTreeItem.SetText | |
| First Time appeared |
Mmaitre314
Mmaitre314 picklescan |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mmaitre314
Mmaitre314 picklescan |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-24T12:49:30.923Z
Reserved: 2026-06-20T12:55:02.882Z
Link: CVE-2025-71354
Updated: 2026-06-24T12:49:10.138Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T18:15:05Z
Github GHSA