CVE-2025-51427High· 7.3▾ TwilightModelScope is vulnerable to arbitrary code injection via a crafted module
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].
modelscope < 1.27.0Upgrade to a patched release:
modelscope 1.27.0Connected by shared product, vendor, weakness, or advisory.