CVE-2024-37065: Skops-Dev Skops
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end user's system when loaded.
Affected products
- Skops-Dev Skops: from 0.6; version 0.6 only
Published 2024-06-04. Last modified 2026-06-17.