CVE-2025-54412
Description
skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain a inconsistency in the OperatorFuncNode which can be exploited to hide the execution of untrusted operator methods. This can then be used in a code reuse attack to invoke seemingly safe functions and escalate to arbitrary code execution with minimal and misleading trusted types. This is fixed in version 0.12.0.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2025-54412? +
How do I check if I'm vulnerable to CVE-2025-54412? +
Related Vulnerabilities
skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain …
An attacker can upload an arbitrary file instead of a plant image.
HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's …
Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users …
When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could …
TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend …