CVE-2025-51427

Published
View on NVD ↗
CVSS v3
7.3
HIGH
CVSS v2
N/A
Affected
2
PROJECTS

Description

An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].

Security disclosures and PoCs for vulnerabilities in AI/ML systems.
GitHubGitHub
ModelScope: bring the notion of Model-as-a-Service to life.
GitHubGitHub
8.95K