UNKNOWN PyPI
Duplicate Advisory: Zip Exploit Crashes Picklescan But Not PyTorch
GHSA-w6mr-mj53-x258
Published ยท Modified
Description
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-7q5r-7gvp-wc82. This link is maintained to preserve external references.
Original Description
picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model archives. By modifying the filename in the ZIP header while keeping the original filename in the directory listing, an attacker can make PickleScan raise a BadZipFile error. However, PyTorch's more forgiving ZIP implementation still allows the model to be loaded, enabling malicious payloads to bypass detection.
References
- WEB https://github.com/mmaitre314/picklescan/security/advisories/GHSA-7q5r-7gvp-wc82
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-1944
- WEB https://github.com/mmaitre314/picklescan/commit/e58e45e0d9e091159c1554f9b04828bbb40b9781
- WEB https://sites.google.com/sonatype.com/vulnerabilities/cve-2025-1944
Ready to move
Start Securing
Free, no credit card | First findings in minutes