GHSA-w6mr-mj53-x258

Suggest an improvement
Source
https://github.com/advisories/GHSA-w6mr-mj53-x258
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-w6mr-mj53-x258/GHSA-w6mr-mj53-x258.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w6mr-mj53-x258
Withdrawn
2025-03-10T18:25:47Z
Published
2025-03-10T12:30:55Z
Modified
2025-03-10T18:40:30Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: Zip Exploit Crashes Picklescan But Not PyTorch
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-7q5r-7gvp-wc82. This link is maintained to preserve external references.

Original Description

picklescan before 0.0.23 is vulnerable to a ZIP archive manipulation attack that causes it to crash when attempting to extract and scan PyTorch model archives. By modifying the filename in the ZIP header while keeping the original filename in the directory listing, an attacker can make PickleScan raise a BadZipFile error. However, PyTorch's more forgiving ZIP implementation still allows the model to be loaded, enabling malicious payloads to bypass detection.

Database specific
{
    "cwe_ids":  [
        "CWE-345"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-03-10T18:25:47Z",
    "nvd_published_at":  "2025-03-10T12:15:10Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / picklescan

Package

Name
picklescan
View open source insights on deps.dev
Purl
pkg:pypi/picklescan

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.23

Affected versions

0.*
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.20
0.0.21
0.0.22

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/03/GHSA-w6mr-mj53-x258/GHSA-w6mr-mj53-x258.json"