highVulnerability

GHSA-cc5p-54x3-hcf8

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-97f8-7cmv-76j2. This link is maintained to preserve external references. ## Original Description picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to embed malicious magic numbers via dynamic eval using the __reduce__ trick. Attackers can craft malicious PyTorch payloads that evade picklescan detection while remaining executable, enabling arbitrary code execution when loaded with torch.load().

Properties

ghsa_id
GHSA-cc5p-54x3-hcf8
summary
Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER
severity
high
cve_id
GHSA-cc5p-54x3-hcf8
is_ghsa_only
true
ghsa_published
2026-06-17T18:35:57Z
source_url
https://github.com/advisories/GHSA-cc5p-54x3-hcf8
ghsa_updated
2026-06-18T14:43:35Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/picklescan

AFFECTS (1)

[Software]pip/picklescan

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')

Explore deeper with Ninja Signal's threat intelligence graph