PickleScan is a tool tracked across 2 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed December 2, 2025; most recent activity December 4, 2025.
PickleScan is a cybersecurity tool/attack framework focused on Python pickle deserialization. Recent reporting describes critical zero-day vulnerabilities in PickleScan that threaten AI models and their supply chains, marking it as a high-severity risk to machine learning deployments and model ecosystems.
Three critical zero-day vulnerabilities have been identified in PickleScan, a tool used for scanning Python pickle files and PyTorch models. These flaws, all rated 9.3 on the CVSS scale, enable attackers to bypass…
Multiple critical zero-day vulnerabilities have been identified in PickleScan, an open-source tool used for scanning machine learning models for malicious code. This tool is widely utilized in the AI community,…