📊 n/a
📝 Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205782
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205782
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205781
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205781
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205780
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205780
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205779
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205779
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205659
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205659
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205639
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205639
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205638
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205638
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 mmaitre314
📝 picklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag bits are modified. By flipping s...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-7445
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 mmaitre314
📝 picklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag bits are modified. By flipping s...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-7445
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 mmaitre314
📝 picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model arc...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-7156
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 mmaitre314
📝 picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model arc...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-7156
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 mmaitre314
📝 picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious mode...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-5523
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 mmaitre314
📝 picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious mode...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-5523
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 mmaitre314
📝 picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-5323
#cybersecurity #infosec #cve #euvd
📊 5.3/10
🏢 mmaitre314
📝 picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-5323
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan vulnerable to Arbitrary File Writing
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205592
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan vulnerable to Arbitrary File Writing
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205592
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan does not block ctypes
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205591
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan does not block ctypes
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205591
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan has Incomplete List of Disallowed Inputs
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205590
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan has Incomplete List of Disallowed Inputs
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205590
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan missing detection when calling pty.spawn
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205589
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan missing detection when calling pty.spawn
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205589
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan Bypasses Unsafe Globals Check using pty.spawn
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205588
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan Bypasses Unsafe Globals Check using pty.spawn
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205588
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205587
#cybersecurity #infosec #cve #euvd
📊 n/a
📝 Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205587
#cybersecurity #infosec #cve #euvd
Stay vigilant. The payload is in the weights. 🛡️
#CyberSecurity #SOCLife #BlueTeam #AISecurity #PickleScan #InfoSec2025 #MachineLearning
Stay vigilant. The payload is in the weights. 🛡️
#CyberSecurity #SOCLife #BlueTeam #AISecurity #PickleScan #InfoSec2025 #MachineLearning
Forget Log4j. In Dec 2025, we’re hunting CVE-2025-23001—a.k.a. "PickleScan."
Attackers are now embedding RCE payloads inside pre-trained AI models (.pkl/.h5). If your devs download a "helper" model from a public repo, you're compromised. 🧵👇
Forget Log4j. In Dec 2025, we’re hunting CVE-2025-23001—a.k.a. "PickleScan."
Attackers are now embedding RCE payloads inside pre-trained AI models (.pkl/.h5). If your devs download a "helper" model from a public repo, you're compromised. 🧵👇
#cybersecurity #devops #CICD #Artifactory https://opsmtrs.com/3tbAFrI
#cybersecurity #devops #CICD #Artifactory https://opsmtrs.com/3tbAFrI
A Silent Threat Rising Inside the AI Supply Chain The security walls guarding modern machine learning systems have always begun with one foundation, the AI model scanner. These scanners were designed to sift…
A Silent Threat Rising Inside the AI Supply Chain The security walls guarding modern machine learning systems have always begun with one foundation, the AI model scanner. These scanners were designed to sift…