Inconsistent MethodNode in skops Python Library Discloses Object Fields
CVE-2025-54413
8.7HIGH
What is CVE-2025-54413?
The skops Python library, used for sharing and shipping scikit-learn based models, has a notable vulnerability due to an inconsistency in the MethodNode. This flaw allows attackers to leverage dot notation to access unexpected object fields, potentially leading to arbitrary code execution at load time. This issue is particularly concerning because it operates under fewer assumptions about trusted types, making it a more significant risk than related vulnerabilities. Users are advised to upgrade to version 12.0.0, where this vulnerability has been addressed.
Affected Version(s)
skops < 12.0.0