Critical Vulnerabilities Found in PickleScan Tool for AI Models

Critical Vulnerabilities Found in PickleScan Tool for AI Models

First seen 4 Dec 2025, 03:41 UTC Infosecurity-MagazineScworld 92% similarity 88.0

Article Content

Browse articles
ThreatCluster

Three critical zero-day vulnerabilities have been identified in PickleScan, a tool used for scanning Python pickle files and PyTorch models. These flaws, all rated 9.3 on the CVSS scale, enable attackers to bypass safeguards and distribute malicious machine learning models undetected. The vulnerabilities include a file extension bypass issue tracked as CVE-2025-10155, as detailed by the JFrog Security Research Team in an advisory published on December 2, 2025.

ThreatCluster AI

Community

Browse all →