CVE-2025-71321
CRITICAL
NVD
CVSS Score
9.8
Severity
CRITICAL
Published
Jun 17, 2026
Vendor
unknown
Description
picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects to overwrite critical system files and achieve denial of service or remote code execution.