Inconsistent MethodNode in skops Python Library Discloses Object Fields
CVE-2025-54413

8.7HIGH

Key Information:

Vendor

Skops-dev

Status
Vendor
CVE Published:
26 July 2025

What is CVE-2025-54413?

The skops Python library, used for sharing and shipping scikit-learn based models, has a notable vulnerability due to an inconsistency in the MethodNode. This flaw allows attackers to leverage dot notation to access unexpected object fields, potentially leading to arbitrary code execution at load time. This issue is particularly concerning because it operates under fewer assumptions about trusted types, making it a more significant risk than related vulnerabilities. Users are advised to upgrade to version 12.0.0, where this vulnerability has been addressed.

Affected Version(s)

skops < 12.0.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54413 : Inconsistent MethodNode in skops Python Library Discloses Object Fields