Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xgj3-g5r2-m8rf

Опубликовано: 04 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.6
CVSS3: 8.1

Описание

picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load().

picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load().

EPSS

Процентиль: 30%
0.00365
Низкий

7.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 месяцев назад

picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for malicious code. Attackers can craft malicious pickle payloads using _operator.methodcaller that evade detection and execute arbitrary code when loaded by pickle.load().

EPSS

Процентиль: 30%
0.00365
Низкий

7.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-502