skops has 4 CVEs on record between 2024 and 2025. The median CVSS is 8.1 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- skops 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2025-54886High· 8.4SKOPS Card.get_model happily allows arbitrary code execution46CVE-2024-37065High· 7.8Skops unsafe deserialization43CVE-2025-54413HighSkops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time41CVE-2025-54412HighSkops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution41
skops vulnerabilities
CVEs affecting skops, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2025-54886High· 8.4SKOPS Card.get_model happily allows arbitrary code execution
SKOPS Card.get_model happily allows arbitrary code execution
▾ Twilightskops · skopsEPSS 0.22%via OSV
CVE-2025-54412HighSkops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
▾ Twilightskops · skopsEPSS 0.14%via OSV
CVE-2025-54413HighSkops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
▾ Twilightskops · skopsEPSS 0.14%via OSV
CVE-2024-37065High· 7.8Skops unsafe deserialization
Skops unsafe deserialization
▾ Twilightskops · skopsEPSS 0.24%via OSV