CVE-2025-1716 affects picklescan before 0.0.21. The scanner failed to classify the Python global pip as unsafe during analysis of Pickle-serialized model artifacts. As a result, an attacker could craft a malicious model whose Pickle payload invokes pip.main() to fetch and install or otherwise execute code from a malicious Python package hosted on a remote repository such as PyPI or GitHub. Because pip was not included in the restricted/unsafe globals set, the malicious model could pass picklescan security checks and be incorrectly presented as safe despite containing a code-execution path through package retrieval and installation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
pip.main() and installation of a malicious package from a remote source. Depending on how the model is subsequently handled, this may result in arbitrary code execution, compromise of the host or runtime environment, supply-chain style package retrieval from attacker-controlled infrastructure, and loss of integrity of ML pipelines or systems processing the model.If you can’t patch tonight, do this now.
pip, pip.main, dynamic package installation behavior, or network-based dependency retrieval. Restrict outbound network access from model scanning and model execution environments, disable or tightly control package installation capabilities, and prefer safer serialization formats where possible. Only accept serialized models from trusted sources and perform analysis in isolated sandboxes.Patch, then assume compromise.
pip is treated as an unsafe global. Re-scan previously approved Pickle-based model artifacts, especially any that were cleared by versions prior to 0.0.21. Review trust decisions for serialized models obtained from untrusted or third-party sources, and validate whether any model loading workflows could have executed package installation or other side effects.2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains only a minimal README and a `setup.py` that executes code at import/setup time. The `setup.py` spawns `curl` to fetch `http://127.0.0.1:8000/exploit.txt` and suppresses stdout/stderr, then proceeds with a normal setuptools `setup()` call. This is not a traditional memory corruption exploit; it is a proof-of-concept demonstrating arbitrary command execution during package installation (a common supply-chain technique), with a hardcoded localhost HTTP endpoint used as the payload source/stager. No `rsac_2025` package directory is present in the provided file listing, suggesting the repository is incomplete or intentionally minimal for demonstration.
Repository contains a minimal Python package with two files: an empty package module `cve-2025-1716/__init__.py` and a `setup.py` that executes an OS command via `os.system()` at import/setup time. The only demonstrated capability is arbitrary command execution when the package is installed or when `setup.py` is run, implemented as `touch /tmp/cve-2025-1716.txt` to drop a marker file. No network functionality, C2, URLs, IPs, or remote endpoints are present; the only fingerprintable observable is the created file path under `/tmp`. This is best characterized as a PoC for install-time code execution (supply-chain style), not a full remote exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.