Database/AI/ML frameworks & serving
picklescan (model scanner): Scanner fails to detect malicious pickles when ZIP flag bits are flipped
CVE-2025-1945AI/ML frameworks & servingcurated
Impact
Scanner fails to detect malicious pickles when ZIP flag bits are flipped
Who can reach it
Customer-supplied PyTorch archive submitted to a provider's "we scan your models" control
What to do
Direct hit on the provider's own control plane. Upgrade picklescan and stop treating a clean scan as proof of safety
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.