Conversation
📗 Scan Summary
🚥 Policy Violations🚨 Security Violations
🔖 Details[ CVE-2025-10156 ] picklescan 0.0.24 (frogbot)Violation Details
An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 picklescan allows a remote attacker to bypass security scans. This is achieved by crafting a ZIP archive containing a file with a bad Cyclic Redundancy Check (CRC), which causes the scanner to halt and fail to analyze the contents for malicious pickle files. When the file incorrectly considered safe is loaded, it can lead to the execution of malicious code. [ CVE-2025-10155 ] picklescan 0.0.24 (frogbot)Violation Details
An Improper Input Validation vulnerability in the scanning logic of mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass pickle files security checks by supplying a standard pickle file with a PyTorch-related file extension. When the pickle file incorrectly considered safe is loaded, it can lead to the execution of malicious code. [ CVE-2025-10157 ] picklescan 0.0.24 (frogbot)Violation Details
A Protection Mechanism Failure vulnerability in mmaitre314 picklescan versions up to and including 0.0.30 allows a remote attacker to bypass the unsafe globals check. This is possible because the scanner performs an exact match for module names, allowing malicious payloads to be loaded via submodules of dangerous packages (e.g., 'asyncio.unix_events' instead of 'asyncio'). When the incorrectly considered safe file is loaded after scan, it can lead to the execution of malicious code. [ XRAY-714109 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass [ CVE-2025-46417 ] picklescan 0.0.24 (frogbot)Violation Details
The unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS after deserialization. [ XRAY-718829 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan is missing detection when calling built-in python library asyncio.unix_events._UnixSubprocessTransport._start [ XRAY-718828 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan is missing detection when calling built-in python cProfile.run [ XRAY-718827 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan is missing detection when calling built-in python cProfile.runctx [ XRAY-718826 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan is missing detection when calling built-in python doctest.debug_script [ XRAY-718825 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcode [ XRAY-718824 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan is missing detection when calling built-in python idlelib.pyshell.ModifiedInterpreter.runcommand [ XRAY-718823 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan is missing detection when calling built-in python idlelib.run.Executive.runcode [ XRAY-718822 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan is missing detection when calling built-in python lib2to3.pgen2.pgen.ParserGenerator.make_label [ XRAY-718821 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan is missing detection when calling built-in python ensurepip._run_pip [ XRAY-718820 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan is missing detection when calling pytorch function torch.utils.bottleneck.main.run_autograd_prof [ XRAY-718812 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan has a missing detection when calling built-in python library idlelib.calltip.get_entity [ XRAY-718811 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip [ XRAY-718810 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan has a missing detection when calling built-in python code.InteractiveInterpreter [ XRAY-718809 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions [ XRAY-718808 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.get_entity [ XRAY-718807 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan has a missing detection when calling built-in python idlelib.debugobj.ObjectTreeItem [ XRAY-718806 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan has a missing detection when calling built-in python lib2to3.pgen2.grammar.Grammar.loads [ XRAY-718805 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan has a missing detection when calling built-in python profile.Profile.runctx [ XRAY-718804 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan has a missing detection when calling built-in python profile.Profile.run [ XRAY-718803 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan has a missing detection when calling built-in python trace.Trace.runctx [ XRAY-718802 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan has a missing detection when calling built-in python trace.Trace.run [ XRAY-718040 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan missing detection when calling pytorch function torch.utils._config_module.load_config [ XRAY-718039 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper [ XRAY-718038 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan missing detection when calling pytorch function torch.utils.data.datapipes.utils.decoder.basichandlers [ XRAY-718037 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan missing detection when calling pytorch function torch.utils.collect_env.run [ XRAY-718036 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan missing detection when calling pytorch function torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expression [ XRAY-718035 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan missing detection when calling pytorch function torch._dynamo.guards.GuardBuilder.get [ XRAY-718034 ] picklescan 0.0.24 (frogbot)Violation Details
Picklescan missing detection when calling pytorch function torch.utils.bottleneck.main.run_cprofile [ CVE-2023-30861 ] flask 2.2.2 (frogbot)Violation DetailsPersistent session cookies in Flask can lead to data leakage or privilege escalation when the application is hosted behind a caching proxy. 🔬 JFrog Research DetailsDescription: The root cause of this issue is the absence of the To exploit this vulnerability, several specific conditions must be met:
Example of vulnerable code: from flask import Flask, session
app = Flask(__name__)
app.secret_key = 'your_secret_key'
@app.route('/')
def index():
session.permanent = True
# Other code logic...
return privateData(user)In this example, a Flask application is used, and the Remediation: Development mitigationsAdd a Development mitigationsDisable the |





trying again