CVE-2025-10157 is a Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to 0.0.30. It allows a remote attacker to bypass the unsafe globals check by exploiting the scanner's exact module name matching, enabling malicious code execution through submodules of dangerous packages. This vulnerability carries a CVSS score of 7.8 (High), indicating a significant risk. An attacker can achieve high impact on confidentiality, integrity, and availability with low attack complexity, though user interaction is required. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite this, the vulnerability has garnered some community discussion and media coverage, highlighting its potential impact on AI model supply chains.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.0.31CPE matchmatch criteria | cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:* | ||
>= 0, <= 0.0.30CPE match | cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.