VDB
Sign up
HIGH7.8

PYSEC-2026-1928

Skops unsafe deserialization

Details

Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/skops
Introduced in: 0.6

No fixed version published yet for skops (pip). Pin to a known-safe version or switch to an alternative.

References