Executive brief
Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
Affected products
- PyPI skops
Junglewise Threat Intelligence
CVE-2025-54413 · Severity: medium · CVSS 4 · Published 2026-07-07
Technologies: skops (PyPI). Vendors: PyPI.
Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time