AVID-2026-R1713
Description
erdogant pypickle pypickle.py save improper authorization (CVE-2025-5175)
Details
A vulnerability was found in erdogant pypickle up to 1.1.5. It has been classified as critical. This affects the function Save of the file pypickle/pypickle.py. The manipulation leads to improper authorization. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Upgrading to version 2.0.0 is able to address this issue. The patch is named 14b4cae704a0bb4eb6723e238f25382d847a1917. It is recommended to upgrade the affected component.
Reason for inclusion in AVID: CVE-2025-5175 describes an improper authorization vulnerability in erdogant pypickle’s Save function (versions up to 1.1.5, patched in 2.0.0). This is a software supply-chain issue in a Python library commonly used in AI/ML pipelines, with a disclosed local-exploit and documented remediation. The CVE clearly identifies a security/safety vulnerability with actionable details and evidence.
References
- NVD entry
- https://vuldb.com/?id.310263
- https://vuldb.com/?ctiid.310263
- https://vuldb.com/?submit.579824
- https://github.com/erdogant/pypickle/issues/3
- https://github.com/erdogant/pypickle/issues/3#issuecomment-2888589652
- https://github.com/erdogant/pypickle/issues/3#issue-3070689116
- https://github.com/erdogant/pypickle/commit/14b4cae704a0bb4eb6723e238f25382d847a1917
- https://github.com/erdogant/pypickle/releases/tag/2.0.0
Affected or Relevant Artifacts
- Developer: erdogant
- Deployer: erdogant
- Artifact Details:
| Type | Name |
|---|---|
| System | pypickle |
Impact
AVID Taxonomy Categorization
- Risk domains: Security
- SEP subcategories: S0100: Software Vulnerability
- Lifecycle stages: L06: Deployment
CVSS
| Version | 3.1 |
| Vector String | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| Base Score | 5.3 |
| Base Severity | 🟠 Medium |
CWE
| ID | Description |
|---|---|
| CWE-285 | Improper Authorization |
| CWE-266 | Incorrect Privilege Assignment |
Other information
- Report Type: Advisory
- Credits:
- Date Reported: 2025-05-26
- Version: 0.3.3
- AVID Entry