CVE-2025-71323 PUBLISHED

picklescan - Remote Code Execution via Unblocked ctypes Module

Assigner: VulnCheck
Reserved: 08.06.2026 Published: 17.06.2026 Updated: 17.06.2026

picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls and accessing raw memory. Attackers can craft malicious pickle files using ctypes.WinDLL to load kernel32.dll and execute arbitrary commands, bypassing sandbox protections and gadget chain detection.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor picklescan
Product picklescan
Versions Default: unaffected
  • affected from 0 to 0.0.33 (excl.)
  • Version 0.0.33 is unaffected

Credits

  • 0x-Apollyon reporter

References

Problem Types

  • Incomplete List of Disallowed Inputs CWE