Description
skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain a inconsistency in the OperatorFuncNode which can be exploited to hide the execution of untrusted operator methods. This can then be used in a code reuse attack to invoke seemingly safe functions and escalate to arbitrary code execution with minimal and misleading trusted types. This is fixed in version 0.12.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22763 | Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution |
Github GHSA |
GHSA-m7f4-hrc6-fwg3 | Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution |
References
History
Mon, 28 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 26 Jul 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain a inconsistency in the OperatorFuncNode which can be exploited to hide the execution of untrusted operator methods. This can then be used in a code reuse attack to invoke seemingly safe functions and escalate to arbitrary code execution with minimal and misleading trusted types. This is fixed in version 0.12.0. | |
| Title | skops' Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Execution | |
| Weaknesses | CWE-351 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-28T13:55:57.057Z
Reserved: 2025-07-21T23:18:10.280Z
Link: CVE-2025-54412
Updated: 2025-07-28T13:55:48.997Z
Status : Deferred
Published: 2025-07-26T04:16:06.597
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-54412
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA