Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-vv6j-3g6g-2pvj. This link is maintained to preserve external references. ### Original Description picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply chain attacks.
AI Analysis
Technical Summary
Picklescan prior to version 0.0.28 does not detect malicious pickle files that use the torch.utils._config_module.load_config function within reduce methods. This evasion allows attackers to embed arbitrary code that executes during the deserialization process (pickle.load), leading to remote code execution risks in supply chain scenarios. The vulnerability is tracked under CWE-502 (Deserialization of Untrusted Data) and has a CVSS 3.1 score of 8.1 (high severity).
Potential Impact
Successful exploitation can lead to remote code execution by loading malicious pickle files that bypass detection mechanisms in Picklescan before 0.0.28. This poses a significant risk in supply chain attacks where malicious serialized data can execute arbitrary code on the target system.
Mitigation Recommendations
A patch is available for Picklescan to address this detection bypass vulnerability. Users should upgrade to version 0.0.28 or later to mitigate the risk. No additional mitigation steps are indicated by the vendor advisory.
Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config
Description
### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-vv6j-3g6g-2pvj. This link is maintained to preserve external references. ### Original Description picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files embedding arbitrary code that evades detection but executes during pickle.load, enabling remote code execution in supply chain attacks.
CVSS v3.1
Score 8.1high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Picklescan prior to version 0.0.28 does not detect malicious pickle files that use the torch.utils._config_module.load_config function within reduce methods. This evasion allows attackers to embed arbitrary code that executes during the deserialization process (pickle.load), leading to remote code execution risks in supply chain scenarios. The vulnerability is tracked under CWE-502 (Deserialization of Untrusted Data) and has a CVSS 3.1 score of 8.1 (high severity).
Potential Impact
Successful exploitation can lead to remote code execution by loading malicious pickle files that bypass detection mechanisms in Picklescan before 0.0.28. This poses a significant risk in supply chain attacks where malicious serialized data can execute arbitrary code on the target system.
Mitigation Recommendations
A patch is available for Picklescan to address this detection bypass vulnerability. Users should upgrade to version 0.0.28 or later to mitigate the risk. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qvp4-q2p5-22gg
- Osv Schema Version
- 1.4.0
- Ecosystems
- ["PyPI"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6aa47eb655bf5e2cf585795e
Added to database: 09/11/2026, 22:20:38 UTC
Last enriched: 09/11/2026, 23:01:26 UTC
Last updated: 09/12/2026, 01:01:23 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.