Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-54413

24
FAUCET Score

CVE-2025-54413 is a critical arbitrary code execution vulnerability affecting skops versions 0.11.0 and below, a Python library for scikit-learn models. It stems from an inconsistency in the MethodNode, allowing attackers to access unexpected object fields via dot notation during model loading. With a CVSS score of 8.7 (HIGH), this vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While more severe than a similar past issue, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
Skops-DevSkops
< 12.0.0CNA affected

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 2nd percentile among its peer group of 11,621 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

pippatch availablevia ghsa
Product: skopsFixed in: 0.12.0

Vendor Advisories (1)

pipGHSA-4v6w-xpmh-gfgphigh

Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time

Jul 25, 2025

References

drive.google.com / drive/folders/1bmVV18mnPbWy21hVYgf51yVJpf78vtB_
github.com / skops-dev/skops/commit/0aeca055509dfb48c1506870aabdd9e247adf603
github.com / skops-dev/skops/releases/tag/v0.12.0
github.com / skops-dev/skops/security/advisories/GHSA-4v6w-xpmh-gfgp
github.com / skops-dev/skops/security/advisories/GHSA-m7f4-hrc6-fwg3