Description
Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2133 | Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded. |
Github GHSA |
GHSA-q49c-6v6g-wgq3 | Skops unsafe deserialization |
References
| Link | Providers |
|---|---|
| https://hiddenlayer.com/sai-security-advisory/skops-june2024 |
|
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2024-08-02T03:43:50.919Z
Reserved: 2024-05-31T14:19:09.799Z
Link: CVE-2024-37065
Updated: 2024-08-02T03:43:50.919Z
Status : Deferred
Published: 2024-06-04T12:15:13.507
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-37065
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA