Mmaitre314 maintains a focused security tooling product, Picklescan, designed to detect and validate untrusted serialized Python objects and protect against deserialization attacks. Vulnerabilities in this product skew strongly toward critical-severity outcomes and center on weaknesses in input validation, data authentication, and exception handling that can undermine the integrity of the scanning logic itself. Defenders deploying deserialization defenses should track this vendor's updates closely, as flaws in validation tooling can have outsized impact on downstream security posture; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mmaitre314 over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-10156CRITICAL An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans. This | Sep 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-71348HIGH picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config function within reduce methods. Attackers can craft pickle files | Jun 21, 2026 | 8.1 | 32 | NO | NO |
CVE-2025-71378HIGH picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attackers to execute arbitrary code. Malicious pickle files bypass p | Jun 21, 2026 | 8.1 | 31 | NO | NO |
CVE-2025-71357HIGH picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickl | Jun 21, 2026 | 8.1 | 31 | NO | NO |
CVE-2025-10155HIGH An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files securi | Sep 17, 2025 | 7.8 | 29 | NO | NO |
CVE-2025-10157HIGH A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check. This is possi | Sep 17, 2025 | 7.8 | 28 | NO | NO |
CVE-2025-1716CRITICAL picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a malicious PyPI package (hosted, for examp | Feb 26, 2025 | 9.8 | 28 | NO | NO |
CVE-2026-56304MEDIUM picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte files via logging.FileHandler class | Jun 20, 2026 | 6.5 | 27 | NO | NO |
CVE-2025-1945CRITICAL picklescan before 0.0.23 fails to detect malicious pickle files inside PyTorch model archives when certain ZIP file flag bits are modified. By flipping specific bits in the ZIP fil | Mar 10, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-1889CRITICAL picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and incl | Mar 3, 2025 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mmaitre314.
Media articles that mention a CVE ID that affects a product developed by Mmaitre314 — matched by CVE ID, not by vendor name.