Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-51427

Опубликовано: 19 мая 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].

A flaw was found in ModelScope. This vulnerability allows a remote attacker to execute arbitrary code by providing a specially crafted module within the configuration file (dey_mini.yaml) under the 'nnet.module' key. Successful exploitation could lead to complete system compromise.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-agent-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-controller-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-router-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-kserve-storage-initializer-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2479894ModelScope: ModelScope: Arbitrary code execution via crafted configuration module

EPSS

Процентиль: 42%
0.00522
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
3 месяца назад

An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].

CVSS3: 7.3
github
3 месяца назад

ModelScope is vulnerable to arbitrary code injection via a crafted module

EPSS

Процентиль: 42%
0.00522
Низкий

8.1 High

CVSS3

Уязвимость CVE-2025-51427