External risk intelligence

Picklescan Improper Input Validation Allows Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-10155

Picklescan is a developer-focused utility library used to scan files for malicious code during local development or build processes. It is not designed to be deployed as an internet-facing service, gateway, or public-facing application, making public network reachability of this specific vulnerability in common deployments very unlikely.

Mmaitre314 Picklescan

before 0.0.31

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects a utility for scanning files, allowing an attacker to bypass security checks with specially crafted pickle files, potentially leading to malicious code execution. The primary concern is to confirm if this specific technology is in use within our environment and to what extent it might be exposed.

  • Allows malicious code through file scans.
  • Understand its use to gauge risk.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted pickle file to a system running the affected software. The software, when processing this file, incorrectly trusts it due to a PyTorch-related file extension, leading to the execution of arbitrary code.

  • Remote attacker can send a malicious file.
  • Software loads a specially crafted pickle file.
  • Malicious code execution is possible.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a remote attacker could trick the affected software into loading a malicious pickle file by disguising it with a PyTorch-related file extension. This could lead to the execution of arbitrary code.

  • Malicious code execution.
  • Malicious pickle file loading.
  • Compromise of system integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in picklescan could allow remote code execution if a specially crafted pickle file is loaded. Application owners or platform teams responsible for the pipeline or local development environments where this tool is used should first identify all instances of picklescan, confirm its reachability and criticality, and then plan remediation.

  • Application or platform teams own resolution.
  • Verify pickle file usage and reachability.
  • Plan remediation based on exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is picklescan?

Picklescan is a developer-focused utility library designed to inspect pickle files for potentially malicious code. Developers typically integrate it into local development workflows or automated build pipelines to safely analyze serialized data structures before loading them.

How does CVE-2025-10155 allow code execution?

The vulnerability involves Improper Input Validation (CWE-20). The scanner fails to correctly vet files that carry specific PyTorch-related extensions, mistakenly flagging them as safe. When the tool processes these disguised malicious pickle files, it inadvertently allows the execution of unauthorized code.

When does this vulnerability trigger?

The flaw is triggered when the scanner processes a malicious pickle file that has been mislabeled with a PyTorch file extension. It does not trigger when scanning files that do not rely on this specific extension-based logic bypass or when processing legitimate, non-malicious data.

Is my system at risk from this CVE?

According to Halo Surface Signal, this risk is very unlikely for most users. Because picklescan is a utility library for development and build processes rather than an internet-facing gateway or public-facing service, it is rarely exposed to the public internet where remote attackers operate.

How should I respond to CVE-2025-10155?

Your first step is to inventory your development and build environments to identify where picklescan is used. Once located, verify if the tool is accessible from untrusted networks. Prioritize updating to version 0.0.31 or later to resolve the input validation issue.

References