id: PYSEC-2026-2663 published: "2026-07-13T15:19:09.174645Z" modified: "2026-07-13T16:04:57.837020Z" aliases: - CVE-2025-51427 - GHSA-fhhq-h4hg-549x summary: ModelScope is vulnerable to arbitrary code injection via a crafted module details: An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. affected: - package: name: modelscope ecosystem: PyPI purl: pkg:pypi/modelscope ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 1.27.0 versions: - 1.0.4 - 1.1.1 - 1.1.3 - 1.10.0 - 1.11.0 - 1.11.1 - 1.12.0 - 1.13.0 - 1.13.1 - 1.13.2 - 1.13.3 - 1.14.0 - 1.15.0 - 1.16.0 - 1.16.1 - 1.17.0 - 1.17.1 - 1.18.0 - 1.18.1 - 1.19.0 - 1.19.1 - 1.19.2 - 1.2.0 - 1.2.1 - 1.20.0 - 1.20.1 - 1.21.0 - 1.21.1 - 1.22.0 - 1.22.1 - 1.22.2 - 1.22.3 - 1.23.0 - 1.23.1 - 1.23.2 - 1.24.0 - 1.24.1 - 1.25.0 - 1.26.0 - 1.3.0 - 1.3.1 - 1.3.2 - 1.4.0 - 1.4.1 - 1.4.2 - 1.5.0 - 1.5.1 - 1.5.2 - 1.6.0 - 1.6.1 - 1.7.0 - 1.7.1 - 1.8.0 - 1.8.0rc0 - 1.8.1 - 1.8.3 - 1.8.4 - 1.9.0 - 1.9.1 - 1.9.2 - 1.9.3 - 1.9.4 - 1.9.5 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2025-51427 - type: WEB url: https://github.com/modelscope/modelscope/issues/1331 - type: WEB url: https://github.com/modelscope/modelscope/pull/1333 - type: WEB url: https://github.com/modelscope/modelscope/commit/75d54927e112261d39598ca08c15b66a7ff3f735 - type: WEB url: https://github.com/JIRUWOZHI/vulnerability-disclosure/blob/main/CVE-2025-51427/CVE_2025_51427.md - type: PACKAGE url: https://github.com/modelscope/modelscope - type: PACKAGE url: https://pypi.org/project/modelscope - type: ADVISORY url: https://github.com/advisories/GHSA-fhhq-h4hg-549x severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L