Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fhhq-h4hg-549x

Опубликовано: 19 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

ModelScope is vulnerable to arbitrary code injection via a crafted module

An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].

Пакеты

Наименование

modelscope

pip
Затронутые версииВерсия исправления

< 1.27.0

1.27.0

EPSS

Процентиль: 41%
0.00522
Низкий

7.3 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.1
redhat
3 месяца назад

An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].

CVSS3: 7.3
nvd
3 месяца назад

An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].

EPSS

Процентиль: 41%
0.00522
Низкий

7.3 High

CVSS3

Дефекты

CWE-94