A vulnerability classified as critical has been found in picklescan up to 1.0.2. This affects the function torch.load. The manipulation leads to improper neutralization of directives in dynamically evaluated code.

This vulnerability is uniquely identified as CVE-2026-53875. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.