Scworld
Critical Vulnerabilities Found in PickleScan Tool for AI Models
First seen 4 Dec 2025, 03:41 UTC
•
•92% similarity
•88.0
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Three critical zero-day vulnerabilities have been identified in PickleScan, a tool used for scanning Python pickle files and PyTorch models. These flaws, all rated 9.3 on the CVSS scale, enable attackers to bypass safeguards and distribute malicious machine learning models undetected. The vulnerabilities include a file extension bypass issue tracked as CVE-2025-10155, as detailed by the JFrog Security Research Team in an advisory published on December 2, 2025.
ThreatCluster AI