skops: Card.get_model does not block arbitrary code execution
Published Aug 8, 2025
8.4
HIGHCVSS 3.1
EPSS 0.22%
Description
skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below, the Card.get_model does not contain any logic to prevent arbitrary code execution. The Card.get_model function supports both joblib and skops for model loading. When loading .skops models, it uses skops' secure loading with trusted type validation, raising errors for untrusted types unless explicitly allowed. However, when non-.zip file formats are provided, the function silently falls back to joblib without warning. Unlike skops, joblib allows arbitrary code execution during loading, bypassing security measures and potentially enabling malicious code execution. This issue is fixed in version 0.13.0.
Affected products
-
- Version < 0.13.0StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
The severity of this vulnerability is rated Moderate, as it does not impact system availability. The effects are confined to the application layer, without compromising the underlying system stability.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2025-54886 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2387191 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-23967 Advisory
- https://github.com/advisories/GHSA-378x-6p4f-8jgm Advisory
- https://github.com/io-no/CVE-Reports/tree/main/CVE-2025-54886
- https://github.com/skops-dev/skops/commit/29d61ea8a92f2bde6830e8f32cc72a1a87211cda x_refsource_MISC
- https://github.com/skops-dev/skops/security/advisories/GHSA-378x-6p4f-8jgm x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2025-54886
- https://www.cve.org/CVERecord?id=CVE-2025-54886
Change history (0)
No recorded changes yet.