Database/AI/ML frameworks & serving
skops (scikit-learn model sharing): Inconsistency in the `Operator` handling lets an untrusted model bypass the safe
CVSS 8.7CVE-2025-54412AI/ML frameworks & servingcurated
Impact
Inconsistency in the Operator handling lets an untrusted model bypass the safe loader
Who can reach it
Customer-supplied skops model file
What to do
Upgrade past 0.11.0; skops is the "safe alternative to pickle" and it too has loader bypasses
References
Related entries
- skops: Method-handling inconsistencyCVE-2025-54413 · skopsHigh
- SGLang: duplicate bootstrap_room values crash or hang the disaggregated schedulerCVE-2026-102634 · SGLang prefill/decode disaggregation (Mooncake KV transfer, bootstrap_room)High
- LightLLM: unbounded key-value writes on the NCCL control channel exhaust worker memoryCVE-2026-103042 · LightLLM NCCL KV-transfer control channel (exposed_set_value)High
- Mooncake transfer engine: zero-length handshake frame crashes the hosting inference processCVE-2026-104433 · Mooncake transfer engine (P2P handshake readString)High
- KubeAI (Ollama engine controller): Injection in `ollamaStartupProbeScript()`CVE-2026-34940 · KubeAI (Ollama engine controller)High
- Xinference: model launch API executes attacker-supplied Python because trust_remote_code is always onCVE-2026-76841 · Xinference (Xorbits Inference) model loaders - trust_remote_codeHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.