GPU VulnDB

Database/AI/ML frameworks & serving

skops (scikit-learn model sharing): Inconsistency in the `Operator` handling lets an untrusted model bypass the safe

CVE-2025-54412AI/ML frameworks & servingcurated

Impact

Inconsistency in the Operator handling lets an untrusted model bypass the safe loader

Who can reach it

Customer-supplied skops model file

What to do

Upgrade past 0.11.0; skops is the "safe alternative to pickle" and it too has loader bypasses

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.