{"id":"CVE-2025-51427","aliases":["PYSEC-2026-2663"],"url":"https://o3.security/vulnerability/CVE-2025-51427","summary":"ModelScope is vulnerable to arbitrary code injection via a crafted module","details":"An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].","published":"2026-05-19T15:31:35Z","modified":"2026-07-13T16:42:27.445121464Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":{"score":0.00522,"percentile":0.4179,"asOf":"2026-08-14"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"modelscope","fixedVersion":"1.27.0"}],"fix":{"url":"https://github.com/modelscope/modelscope/pull/1333","label":"modelscope/modelscope#1333"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-51427"},{"type":"WEB","url":"https://github.com/modelscope/modelscope/issues/1331"},{"type":"WEB","url":"https://github.com/modelscope/modelscope/pull/1333"},{"type":"WEB","url":"https://github.com/modelscope/modelscope/commit/75d54927e112261d39598ca08c15b66a7ff3f735"},{"type":"WEB","url":"https://github.com/JIRUWOZHI/vulnerability-disclosure/blob/main/CVE-2025-51427/CVE_2025_51427.md"},{"type":"PACKAGE","url":"https://github.com/modelscope/modelscope"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-13T16:42:27.445121464Z"}}