pypi

picklescan

View on pypi registry
100 Total advisories
100 Vulnerabilities
0 Malware

Dependency scanning

Check whether picklescan is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

CRITICAL 9.8
PyPI

CVE-2026-56315

PickleScan has multiple stdlib modules with direct RCE not in blocklist

CRITICAL 9.8
PyPI

GHSA-g7vj-qw6x-g3p8

Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist

HIGH 8.1
PyPI

GHSA-x36p-c636-788x

Duplicate Advisory: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

HIGH 8.1
PyPI

GHSA-q8qp-8jq6-78mc

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

HIGH 8.1
PyPI

GHSA-mg57-j93w-g3c7

Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx

HIGH 8.1
PyPI

GHSA-gq8p-2329-gh3x

Duplicate Advisory: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

HIGH 8.1
PyPI

CVE-2025-71365

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

HIGH 8.1
PyPI

CVE-2025-71370

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

HIGH 8.1
PyPI

CVE-2025-71341

Picklescan has a missing detection when calling built-in python profile.Profile.runctx

HIGH 8.1
PyPI

CVE-2025-71376

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

HIGH 8.1
PyPI

CVE-2025-71348

Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config

UNKNOWN
PyPI

CVE-2025-71357

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

UNKNOWN
PyPI

CVE-2025-71351

Picklescan missing detection when calling built-in python library function timeit.timeit()

HIGH 8.1
PyPI

GHSA-qvp4-q2p5-22gg

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config

UNKNOWN
PyPI

GHSA-fh2f-24rh-r2vq

Duplicate Advisory: Picklescan missing detection when calling built-in python library function timeit.timeit()

HIGH 8.1
PyPI

GHSA-8mc5-7w9m-fqv6

Duplicate Advisory: Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand

UNKNOWN
PyPI

CVE-2025-71378

Picklescan is missing detection when calling built-in Python cProfile.runctx

HIGH 8.1
PyPI

GHSA-fcqg-3mwf-cfcf

Duplicate Advisory: Picklescan is missing detection when calling built-in Python cProfile.runctx

UNKNOWN
PyPI

GHSA-cc5p-54x3-hcf8

Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

CRITICAL 9.8
PyPI

GHSA-6v84-v468-3c7f

Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs

CRITICAL 9.8
PyPI

GHSA-j6c9-qvp8-699f

Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call

CRITICAL 9.8
PyPI

GHSA-5rph-q42j-36j9

Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

HIGH 8.8
PyPI

GHSA-5gp7-4733-2w2v

Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn

CRITICAL 9.8
PyPI

GHSA-4mpj-78p6-rj59

Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass

UNKNOWN
PyPI

GHSA-4p4h-9gvq-7xfg

Duplicate Advisory: Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate

HIGH 8.1
PyPI

CVE-2025-71344

Picklescan is missing detection when calling built-in python ensurepip._run_pip

UNKNOWN
PyPI

CVE-2026-56304

picklescan vulnerable to arbitrary file create using logging.FileHandler

HIGH 8.1
PyPI

CVE-2025-71354

Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem

HIGH 8.1
PyPI

CVE-2025-71361

Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip

HIGH 8.1
PyPI

CVE-2025-71339

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length

HIGH 8.1
PyPI

CVE-2025-71358

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity

UNKNOWN
PyPI

CVE-2026-53875

Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

UNKNOWN
PyPI

CVE-2026-53875

Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER

CRITICAL 9.8
PyPI

CVE-2025-1716

CVE-2025-1716

UNKNOWN
PyPI

CVE-2025-71347

Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.param_eval

UNKNOWN
PyPI

CVE-2025-71374

Picklescan has a missing detection when calling built-in python profile.Profile.run

UNKNOWN
PyPI

CVE-2025-71364

Picklescan is missing detection when calling built-in python library asyncio.unix_events._UnixSubprocessTransport._start

UNKNOWN
PyPI

CVE-2025-71371

Picklescan has a missing detection when calling built-in python code.InteractiveInterpreter

UNKNOWN
PyPI

CVE-2025-71363

Picklescan is missing detection when calling built-in python cProfile.run

UNKNOWN
PyPI

CVE-2025-71343

Picklescan is missing detection when calling built-in python lib2to3.pgen2.pgen.ParserGenerator.make_label

UNKNOWN
PyPI

CVE-2025-71372

Picklescan is vulnerable to RCE via missing detection when calling numpy.f2py.crackfortran.getlincoef

UNKNOWN
PyPI

CVE-2025-71356

Picklescan missing detection when calling pytorch function torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression

UNKNOWN
PyPI

CVE-2025-71349

Picklescan has a missing detection when calling built-in python trace.Trace.run

UNKNOWN
PyPI

CVE-2025-71340

Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode

UNKNOWN
PyPI

CVE-2025-71362

Picklescan missing detection when calling numpy.f2py.crackfortran.getlincoef

UNKNOWN
PyPI

CVE-2025-71369

Picklescan missing detection when calling pytorch function torch.utils.data.datapipes.utils.decoder.basichandlers

UNKNOWN
PyPI

CVE-2025-71368

Picklescan is missing detection when calling built-in python doctest.debug_script

UNKNOWN
PyPI

CVE-2025-71373

Picklescan is vulnerable to RCE through missing detection when calling built-in python operator.methodcaller

UNKNOWN
PyPI

CVE-2025-71366

Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile

UNKNOWN
PyPI

CVE-2025-71359

Picklescan has a missing detection when calling built-in python lib2to3.pgen2.grammar.Grammar.loads

UNKNOWN
PyPI

CVE-2025-71360

Picklescan has a missing detection when calling built-in python library idlelib.calltip.get_entity

UNKNOWN
PyPI

CVE-2025-71367

Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.attrgetter

UNKNOWN
PyPI

CVE-2025-71375

Picklescan is vulnerable to RCE via missing detection when calling built-in python _operator.methodcaller

UNKNOWN
PyPI

CVE-2025-46417

Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate

UNKNOWN
PyPI

CVE-2025-71342

Picklescan is missing detection when calling built-in python idlelib.run.Executive.runcode

UNKNOWN
PyPI

CVE-2025-71353

Picklescan missing detection when calling pytorch function torch._dynamo.guards.GuardBuilder.get

UNKNOWN
PyPI

CVE-2025-71352

Picklescan has a missing detection when calling built-in python trace.Trace.runctx

UNKNOWN
PyPI

CVE-2025-71355

Picklescan failed to detect to some unsafe global function in Numpy library

UNKNOWN
PyPI

CVE-2025-71345

Picklescan is missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_autograd_prof

UNKNOWN
PyPI

CVE-2025-71350

Picklescan missing detection when calling pytorch function torch.utils.collect_env.run

HIGH 8.8
PyPI

CVE-2025-71322

Picklescan Bypasses Unsafe Globals Check using pty.spawn

CRITICAL 9.8
PyPI

CVE-2025-71323

Picklescan does not block ctypes

UNKNOWN
PyPI

CVE-2025-71321

Picklescan vulnerable to Arbitrary File Writing

UNKNOWN
PyPI

CVE-2025-71320

Picklescan has Incomplete List of Disallowed Inputs

UNKNOWN
PyPI

CVE-2026-53874

picklescan missing detection by simple obfuscation of a `builtins.eval` call

HIGH 7.5
PyPI

CVE-2026-53872

picklescan has Arbitrary file read using `io.FileIO`

UNKNOWN
PyPI

CVE-2025-71325

Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

UNKNOWN
PyPI

CVE-2025-71344

Picklescan is missing detection when calling built-in python ensurepip._run_pip

UNKNOWN
PyPI

CVE-2025-71321

Picklescan vulnerable to Arbitrary File Writing

HIGH 7.5
PyPI

CVE-2026-53872

picklescan has Arbitrary file read using `io.FileIO`

UNKNOWN
PyPI

CVE-2025-71361

Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip

UNKNOWN
PyPI

CVE-2025-71325

Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass

UNKNOWN
PyPI

CVE-2026-53874

picklescan missing detection by simple obfuscation of a `builtins.eval` call

HIGH 8.8
PyPI

CVE-2025-71322

Picklescan Bypasses Unsafe Globals Check using pty.spawn

UNKNOWN
PyPI

CVE-2025-71358

Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity

UNKNOWN
PyPI

CVE-2025-71320

Picklescan has Incomplete List of Disallowed Inputs

UNKNOWN
PyPI

CVE-2025-71339

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran._eval_length

CRITICAL 9.8
PyPI

CVE-2025-71323

Picklescan does not block ctypes

UNKNOWN
PyPI

CVE-2025-71354

Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem

CRITICAL 10.0
PyPI

CVE-2026-3490

PickleScan's pkgutil.resolve_name has a universal blocklist bypass

CRITICAL 9.8
PyPI

CVE-2026-53873

PickleScan's profile.run blocklist mismatch allows exec() bypass

CRITICAL 9.8
PyPI

CVE-2026-53873

PickleScan's profile.run blocklist mismatch allows exec() bypass

CRITICAL 10.0
PyPI

CVE-2026-3490

PickleScan's pkgutil.resolve_name has a universal blocklist bypass

HIGH 7.8
PyPI

CVE-2025-71378

CVE-2025-71378

HIGH 7.8
PyPI

CVE-2025-71348

CVE-2025-71348

HIGH 7.8
PyPI

CVE-2025-71357

CVE-2025-71357

UNKNOWN
PyPI

CVE-2026-56304

CVE-2026-56304

CRITICAL 9.8
PyPI

GHSA-rmpp-8wf5-xx5q

Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing

HIGH 7.5
PyPI

GHSA-5v23-73v4-w2fp

Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO`

CRITICAL 9.8
PyPI

GHSA-7f79-rvx6-vxc4

Duplicate Advisory: Picklescan does not block ctypes

CRITICAL 10.0
PyPI

GHSA-82fg-2r99-h7v6

Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass

HIGH 7.5
PyPI

CVE-2025-10156

Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check

HIGH 8.3
PyPI

CVE-2025-10157

Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports

HIGH 7.8
PyPI

CVE-2025-10155

Picklescan Bypass is Possible via File Extension Mismatch

HIGH 7.8
PyPI

CVE-2025-10157

CVE-2025-10157

CRITICAL 9.8
PyPI

CVE-2025-10156

CVE-2025-10156

HIGH 7.8
PyPI

CVE-2025-10155

CVE-2025-10155

UNKNOWN
PyPI

GHSA-vqmv-47xg-9wpr

Picklescan missing detection when calling pty.spawn

UNKNOWN
PyPI

GHSA-j424-mc44-f4hj

Duplicate Advisory: Picklescan Bypass is Possible via File Extension Mismatch

UNKNOWN
PyPI

GHSA-4vr7-g93g-cf6m

Duplicate Advisory: Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes