Database/AI/ML frameworks & serving
picklescan: `scan_pytorch` bypass via forged magic numbers
CVSS 7.1CVE-2026-53875AI/ML frameworks & servingcurated
Impact
scan_pytorch bypass via forged magic numbers
Who can reach it
Customer-supplied model file
What to do
Upgrade to 1.0.3+. There is no complete fix for pickle scanning — this is the fifth bypass in the same tool
References
Related entries
- picklescan: ZIP manipulation crashes the scanner (scan bypass by DoS)CVE-2025-1944 · picklescanMedium
- picklescan: Misses `idlelib.pyshell.ModifiedInterpreter.runcode` gadgetCVE-2025-71340 · picklescanHigh
- picklescan: Misses `idlelib.run.Executive.runcode` gadgetCVE-2025-71342 · picklescanHigh
- picklescan: Improper input validation lets a crafted pickle evade scanningCVE-2025-10155 · picklescanHigh
- torchvision (GIF decoder): Out-of-bounds heap read in `read_from_tensor` GIF decodeCVE-2026-65918 · torchvision (GIF decoder)High
- MLflow: model version creation reads another user's run artifacts without READ permissionCVE-2026-69148 · MLflow tracking server (CreateModelVersion source run/model validation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.