logo

Critical PickleScan Vulnerabilities Expose AI Model Supply Chains

ID: 8d6dbab8-6b98-5034-a387-b21713f00c95

STIX ID: report--8d6dbab8-6b98-5034-a387-b21713f00c95

Feed Name: Infosecurity Magazine (News)

Threat Score
72/100

Date Published: 2025-12-02

Date Updated: 2026-04-22

...
...

Three critical zero-day vulnerabilities (CVE-2025-10155, CVE-2025-10156, CVE-2025-10157) were disclosed in PickleScan — a popular scanner for Python pickle files and PyTorch models — enabling attackers to bypass scans via file-extension misclassification, ZIP CRC manipulation, and import-blacklist evasion; each flaw is rated CVSS 9.3, a proof-of-concept was demonstrated, and maintainers patched the issues (update to PickleScan 0.0.31) while recommending layered defenses and safer model formats like Safetensors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.