What it is
PickleScan often sits in the safety path for AI model ingestion. A scanner bypass matters because teams treat a clean scan as permission to load a model archive, and loading a pickle runs code.
How it happens
CVE-2025-10156 affects PickleScan before 0.0.31. A ZIP-based model archive with a deliberately broken checksum can make the scan error out instead of inspecting the pickle inside. If the surrounding workflow treats that error as a pass, the archive is loaded without ever being checked.
What an attacker gets
If an affected PickleScan release screens untrusted ZIP, PyTorch, or pickle-containing archives and the workflow ignores scan errors, a malicious model can reach the loader, and loading it runs the attacker's code with the permissions of your training, inference, or CI process.
// what fixvibe reports
What FixVibe reports
Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.
How to fix it
Upgrade `picklescan` to 0.0.31 or newer, regenerate the active Python lockfile, and rebuild every CI, model-ingestion, training, inference, notebook, worker, or security-scanning runtime that uses it. Make scan errors fail closed, keep model artifacts provenance-checked, and use only benign archive/model smoke tests for verification.
