CVE-2025-54413 is a critical arbitrary code execution vulnerability affecting skops versions 0.11.0 and below, a Python library for scikit-learn models. It stems from an inconsistency in the MethodNode, allowing attackers to access unexpected object fields via dot notation during model loading. With a CVSS score of 8.7 (HIGH), this vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While more severe than a similar past issue, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Skops-Dev | Skops | < 12.0.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.