CVE-2025-1945 is a critical vulnerability affecting mmaitre314 picklescan versions prior to 0.0.23. It allows attackers to embed malicious pickle files within PyTorch model archives by manipulating ZIP file flag bits, bypassing PickleScan's detection. This flaw has a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low complexity, and potential for complete compromise (arbitrary code execution). There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.0.23CPE matchmatch criteria | cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:* | ||
>= 0.0.1, < 0.0.23CPE match | cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.