picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model archives. By modifying the filename in the ZIP header while keeping the original filename in the directory listing, an attacker can make PickleScan raise a BadZipFile error. However, PyTorch's more forgiving ZIP implementation still allows the model to be loaded, enabling malicious payloads to bypass detection.
History

Wed, 19 Mar 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mmaitre314
Mmaitre314 picklescan
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mmaitre314:picklescan:*:*:*:*:*:*:*:*
Vendors & Products Mmaitre314
Mmaitre314 picklescan
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Mon, 10 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Mar 2025 11:45:00 +0000

Type Values Removed Values Added
Description picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model archives. By modifying the filename in the ZIP header while keeping the original filename in the directory listing, an attacker can make PickleScan raise a BadZipFile error. However, PyTorch's more forgiving ZIP implementation still allows the model to be loaded, enabling malicious payloads to bypass detection.
Title picklescan ZIP archive manipulation attack leads to crash
Weaknesses CWE-345
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Sonatype

Published: 2025-03-10T11:30:32.896Z

Updated: 2025-03-10T12:09:36.612Z

Reserved: 2025-03-04T12:59:33.809Z

Link: CVE-2025-1944

cve-icon Vulnrichment

Updated: 2025-03-10T12:09:21.792Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-10T12:15:10.967

Modified: 2025-03-19T16:11:29.113

Link: CVE-2025-1944

cve-icon Redhat

No data.