Executive brief
ModelScope is an open-source machine learning library that provides unified access to AI models for inference, training, and evaluation tasks. The library uses Python's unsafe YAML parser when loading model configuration files, allowing attackers to execute arbitrary code by crafting malicious model repositories. Users who load a poisoned model could have their systems compromised without additional interaction.
Technical details
ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, which permits arbitrary Python object construction through YAML tags. An attacker can craft a malicious model repository with a poisoned configuration file containing YAML deserialization gadgets that execute code during model loading. The vulnerability requires a user to load or download a malicious model, but no authentication is required and exploitation occurs automatically upon parsing the configuration. The impact is remote code execution in the context of the user running ModelScope. A fix would involve switching to yaml.SafeLoader or yaml.safe_load() to restrict deserialization to basic data types.
Affected products
- ModelScope ModelScope <1.40.2
Timeline
- 2026-09-01: disclosed