Safety vulnerability ID: 71782
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded. See CVE-2024-37065.
Latest version: 0.11.0
A set of tools, related to machine learning in production.
Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded. See CVE-2024-37065.
MISC:https://hiddenlayer.com/sai-security-advisory/skops-june2024: https://hiddenlayer.com/sai-security-advisory/skops-june2024
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application