{"id":"CVE-2025-71339","aliases":["GHSA-6556-fwc2-fg2p","PYSEC-2026-1783"],"url":"https://o3.security/vulnerability/CVE-2025-71339","summary":"Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran._eval_length Gadget","details":"### Summary\n\nPicklescan uses the `numpy.f2py.crackfortran._eval_length` function (a NumPy F2PY helper) to execute arbitrary Python code during unpickling.\n\n### Details\n\nPicklescan fails to detect a malicious pickle that uses the gadget `numpy.f2py.crackfortran._eval_length` in `__reduce__`, allowing arbitrary command execution when the pickle is loaded. A crafted object returns this function plus attacker‑controlled arguments; the scan reports the file as safe, but pickle.load() triggers execution.\n\n### PoC\n```python\nclass PoC:\n    def __reduce__(self):\n        from numpy.f2py.crackfortran import _eval_length\n        return _eval_length, (\"__import__('os').system('whoami')\", None)\n```\n\n### Impact\n\n- Arbitrary code execution on the victim machine once they load the “scanned as safe” pickle / model file.\n- Affects any workflow relying on Picklescan to vet untrusted pickle / PyTorch artifacts.\n- Enables supply‑chain poisoning of shared model files.\n\n### Credits\n- [ac0d3r](https://github.com/ac0d3r)\n- [Tong Liu](https://lyutoon.github.io), Institute of information engineering, CAS","published":"2026-06-22T21:04:41.267Z","modified":"2026-08-12T03:51:26.342530399Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"picklescan","fixedVersion":"0.0.33"}],"fix":{"url":"https://github.com/mmaitre314/picklescan/pull/53","label":"mmaitre314/picklescan#53"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71339.json"},{"type":"ADVISORY","url":"https://github.com/mmaitre314/picklescan/security/advisories/GHSA-6556-fwc2-fg2p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71339"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/picklescan-arbitrary-code-execution-via-numpy-f2py-crackfortran-eval-length-gadget"},{"type":"WEB","url":"https://github.com/mmaitre314/picklescan/pull/53"},{"type":"WEB","url":"https://github.com/mmaitre314/picklescan/commit/70c1c6c31beb6baaf52c8db1b6c3c0e84a6f9dab"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6556-fwc2-fg2p"},{"type":"PACKAGE","url":"https://github.com/mmaitre314/picklescan"},{"type":"WEB","url":"https://github.com/mmaitre314/picklescan/releases/tag/v0.0.33"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/picklescan/PYSEC-2026-1783.yaml"},{"type":"WEB","url":"https://pypi.org/project/picklescan"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.342530399Z"}}