FixVibe

// code / spotlight

PickleScan ZIP CRC Bypass Advisory

A vulnerable PickleScan dependency can miss malicious model archives when scans fail open.

What it is

PickleScan often sits in the safety path for AI model ingestion. A scanner bypass matters because teams treat a clean scan as permission to load a model archive, and loading a pickle runs code.

How it happens

CVE-2025-10156 affects PickleScan before 0.0.31. A ZIP-based model archive with a deliberately broken checksum can make the scan error out instead of inspecting the pickle inside. If the surrounding workflow treats that error as a pass, the archive is loaded without ever being checked.

What an attacker gets

If an affected PickleScan release screens untrusted ZIP, PyTorch, or pickle-containing archives and the workflow ignores scan errors, a malicious model can reach the loader, and loading it runs the attacker's code with the permissions of your training, inference, or CI process.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade `picklescan` to 0.0.31 or newer, regenerate the active Python lockfile, and rebuild every CI, model-ingestion, training, inference, notebook, worker, or security-scanning runtime that uses it. Make scan errors fail closed, keep model artifacts provenance-checked, and use only benign archive/model smoke tests for verification.

// run it on your own app

Ship करते रहें, FixVibe नज़र रखे रहेगा।

Connect a GitHub repo to check its code, dependencies and workflows.

सोर्स कोड
198
इस category में चलाए गए tests
modules
155
समर्पित सोर्स कोड जाँचें
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// latest checks · practical fixes · ship with confidence

PickleScan ZIP CRC Bypass Advisory: what it is and how to fix it · FixVibe