Arbitrary Code Execution in Modelscope/ms-swift Library by Vendor
CVE-2025-50472

9.8CRITICAL

Key Information:

Vendor

Modelscope

Vendor
CVE Published:
1 August 2025

What is CVE-2025-50472?

The Modelscoop/ms-swift library, through version 2.6.1, is susceptible to a vulnerability that allows attackers to execute arbitrary code via deserialization of untrusted data. This occurs within the load_model_meta() function of the ModelFileSystemCache() class, where maliciously crafted serialized .mdl payloads can be utilized. Exploiting the function's reliance on pickle.load(), attackers can deceive users into loading a seemingly innocuous checkpoint during training, leading to remote code execution without detection. The payload's hidden nature complicates detection, allowing adversaries to run arbitrary code while the legitimate model training process appears unaffected, keeping the user unaware of the threat.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.