HIGH7.3
PYSEC-2026-2663
ModelScope is vulnerable to arbitrary code injection via a crafted module
Quick fix
PYSEC-2026-2663 — modelscope: upgrade to the fixed version with the command below.
pip install --upgrade 'modelscope>=1.27.0'Details
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-51427[ADVISORY]
- https://github.com/modelscope/modelscope/issues/1331[WEB]
- https://github.com/modelscope/modelscope/pull/1333[WEB]
- https://github.com/modelscope/modelscope/commit/75d54927e112261d39598ca08c15b66a7ff3f735[WEB]
- https://github.com/JIRUWOZHI/vulnerability-disclosure/blob/main/CVE-2025-51427/CVE_2025_51427.md[WEB]
- https://github.com/modelscope/modelscope[PACKAGE]
- https://pypi.org/project/modelscope[PACKAGE]
- https://github.com/advisories/GHSA-fhhq-h4hg-549x[ADVISORY]