logo

PickleScan 0-Day Vulnerabilities Enable Arbitrary Code Execution via Malicious PyTorch Models

ID: f0402c8f-cf9b-5d20-9e88-efe599e04555

STIX ID: report--f0402c8f-cf9b-5d20-9e88-efe599e04555

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Abinaya

...
...

Multiple critical zero‑day vulnerabilities (CVE-2025-10155, CVE-2025-10156, CVE-2025-10157) were discovered in PickleScan — a tool used to scan PyTorch models saved with Python pickle — that allow attackers to bypass detection (via file-extension confusion, corrupted ZIP CRCs, and blocklist/unsafe-globals evasion) and achieve arbitrary code execution when models are loaded; JFrog reported the flaws and a fix was released in PickleScan v0.0.31, with users urged to upgrade and adopt layered defenses such as sandboxes and safer formats like Safetensors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.