Описание
ModelScope is vulnerable to arbitrary code injection via a crafted module
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-51427
- https://github.com/modelscope/modelscope/issues/1331
- https://github.com/modelscope/modelscope/pull/1333
- https://github.com/modelscope/modelscope/commit/75d54927e112261d39598ca08c15b66a7ff3f735
- https://github.com/JIRUWOZHI/vulnerability-disclosure/blob/main/CVE-2025-51427/CVE_2025_51427.md
Пакеты
Наименование
modelscope
pip
Затронутые версииВерсия исправления
< 1.27.0
1.27.0
Связанные уязвимости
CVSS3: 8.1
redhat
3 месяца назад
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].
CVSS3: 7.3
nvd
3 месяца назад
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].