CVE-2025-10156
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-17

Last updated on: 2025-10-02

Assigner: JFrog

Description
An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans. This is achieved by crafting a ZIP archive containing a file with a bad Cyclic Redundancy Check (CRC), which causes the scanner to halt and fail to analyze the contents for malicious pickle files.Β When the file incorrectly considered safe is loaded, it can lead to the execution of malicious code.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-17
Last Modified
2025-10-02
Generated
2026-05-07
AI Q&A
2025-09-17
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
mmaitre314 picklescan to 0.0.31 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-755 The product does not handle or incorrectly handles an exceptional condition.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an improper handling of exceptional conditions in the ZIP archive scanning component of mmaitre314 picklescan. A remote attacker can craft a ZIP archive containing a file with a bad Cyclic Redundancy Check (CRC), causing the scanner to stop scanning and fail to detect malicious pickle files inside. As a result, malicious code can be executed when the incorrectly considered safe file is loaded.


How can this vulnerability impact me? :

This vulnerability can allow a remote attacker to bypass security scans by exploiting a malformed ZIP archive, leading to the execution of malicious code on your system without detection.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart