Database/AI/ML frameworks & serving
picklescan: Misses `idlelib.run.Executive.runcode` gadget
CVSS 8.1CVE-2025-71342AI/ML frameworks & servingcurated
Impact
Misses idlelib.run.Executive.runcode gadget
Who can reach it
Customer-supplied pickle
What to do
Upgrade to 0.0.30+; treat gadget denylists as best-effort only
References
Related entries
- picklescan: Improper input validation lets a crafted pickle evade scanningCVE-2025-10155 · picklescanHigh
- picklescan: `scan_pytorch` bypass via forged magic numbersCVE-2026-53875 · picklescanHigh
- picklescan: ZIP manipulation crashes the scanner (scan bypass by DoS)CVE-2025-1944 · picklescanMedium
- picklescan: Misses `idlelib.pyshell.ModifiedInterpreter.runcode` gadgetCVE-2025-71340 · picklescanHigh
- JupyterLab: pasted cell keeps metadata.trusted, running script in the authenticated originCVE-2026-102831 · JupyterLab / Jupyter Notebook / JupyterLite (system-clipboard cell paste)High
- Keras (archive extraction utils): Path traversal in `keras/src/utils/file_utils.py`CVE-2026-11816 · Keras (archive extraction utils)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.