Arbitrary Code Execution Vulnerability in ModelScope by ModelScope Inc.
CVE-2026-84202
8.7HIGH
What is CVE-2026-84202?
ModelScope utilizes PyYAML's unsafe yaml.Loader to handle model configuration files, which can lead to arbitrary code execution. Malicious actors may create compromised model repositories containing these files, enabling them to execute harmful code upon loading by unsuspecting users. This security flaw poses significant risks, particularly for users integrating external models.
Affected Version(s)
modelscope 0 <= 1.40.0
