skops vulnerabilities
CVEs whose affected-version data names the skops package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2025-54886High· 8.4SKOPS Card.get_model happily allows arbitrary code execution
SKOPS Card.get_model happily allows arbitrary code execution
▾ Twilightskops · skopsEPSS 0.22%via OSV
CVE-2025-54412HighSkops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
▾ Twilightskops · skopsEPSS 0.14%via OSV
CVE-2025-54413HighSkops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
▾ Twilightskops · skopsEPSS 0.14%via OSV
CVE-2024-37065High· 7.8Skops unsafe deserialization
Skops unsafe deserialization
▾ Twilightskops · skopsEPSS 0.24%via OSV