FixVibe

// 代码 / 聚焦

PickleScan ZIP CRC Bypass Advisory

A vulnerable PickleScan dependency can miss malicious model archives when scans fail open.

What it is

PickleScan often sits in the safety path for AI model ingestion. A scanner bypass matters because teams treat a clean scan as permission to load a model archive, and loading a pickle runs code.

How it happens

CVE-2025-10156 affects PickleScan before 0.0.31. A ZIP-based model archive with a deliberately broken checksum can make the scan error out instead of inspecting the pickle inside. If the surrounding workflow treats that error as a pass, the archive is loaded without ever being checked.

What an attacker gets

If an affected PickleScan release screens untrusted ZIP, PyTorch, or pickle-containing archives and the workflow ignores scan errors, a malicious model can reach the loader, and loading it runs the attacker's code with the permissions of your training, inference, or CI process.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade `picklescan` to 0.0.31 or newer, regenerate the active Python lockfile, and rebuild every CI, model-ingestion, training, inference, notebook, worker, or security-scanning runtime that uses it. Make scan errors fail closed, keep model artifacts provenance-checked, and use only benign archive/model smoke tests for verification.

// 在你自己的应用上跑一遍

放心继续发布,FixVibe 持续帮你看守风险。

Connect a GitHub repo to check its code, dependencies and workflows.

源代码
198
本类别中触发的测试
模块
155
专属 源代码 检查
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// 最新检查 · 实用修复 · 安心发布

PickleScan ZIP CRC Bypass Advisory: what it is and how to fix it · FixVibe