GHSA-769v-p64c-89pr · Severity: medium · Ecosystem: pip — PyTorch Model Files Can Bypass Pickle Scanners via Unexpected Pickle Extensions
picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An attacker could craft a malicious model that uses Pickle and include a malicious pickle file with a non-standard file extension. Because the malicious pickle file inclusion is not considered as part of the scope of picklescan, the file would pass security checks and appear to be safe, when it could instead prove to be problematic.
Conclusion & alert: CVE-2025-1889 is rated Exploit Available (50/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.36%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.06% | 0.36% | +0.30% |
| 2 | 2026-05-11 | 0.05% | 0.06% | +0.01% |
| 3 | 2026-05-10 | — | 0.05% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 4.0 | MEDIUM |
|
— | — | 103e4ec9-0a87-450b-af77-479448ddef11 |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-769v-p64c-89pr · Severity: medium · Ecosystem: pip — PyTorch Model Files Can Bypass Pickle Scanners via Unexpected Pickle Extensions
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| mmaitre314 | picklescan | < 0.0.22 | cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/mmaitre314/picklescan/security/advisories/GHSA-655q-fx9r-782v | Exploit Third Party Advisory |
| https://www.sonatype.com/security-advisories/cve-2025-1889 |