CVE-2025-10155 is an Improper Input Validation vulnerability in mmaitre314 picklescan versions up to 0.0.30. This flaw allows attackers to bypass security checks by disguising malicious pickle files as safe PyTorch files, leading to arbitrary code execution upon loading. Rated 7.8 HIGH, it requires user interaction (UI:R) and local access (AV:L) but can result in high impact to confidentiality, integrity, and availability. While no public exploits or active exploitation are reported, the vulnerability has garnered community attention and media coverage, indicating its potential significance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.0.31CPE matchmatch criteria | cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:* | ||
>= 0, <= 0.0.30CPE match | cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.