CVE-2024-37065High· 7.8▾ TwilightSkops unsafe deserialization
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded.
skops >= 0.6, <= 0.9Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-54412HighSkops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
CVE-2025-54413HighSkops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
CVE-2025-54886High· 8.4SKOPS Card.get_model happily allows arbitrary code execution