modelscope
ModelScope: bring the notion of Model-as-a-Service to life.
Activity
- Latest release
- 5d ago
- Total releases
- 92
- Cadence
- ~11 days
- Last 12 months
- 20
Reach
- Stars
- 9.1k
Details
- License
- Apache-2.0
- First release
- Dec 07, 2022
| Version | Released | |
|---|---|---|
1.40.0
minor
| ||
1.39.1
patch
| ||
1.39.0
minor
| ||
1.38.1
patch
| ||
1.38.0
minor
| ||
1.37.1
patch
| ||
1.37.0
minor
| ||
1.36.3
patch
| ||
1.36.2
patch
| ||
1.36.1
patch
| ||
1.36.0
minor
| ||
1.35.4
patch
| ||
1.35.3
patch
| ||
1.35.2
patch
| ||
1.35.1
patch
| ||
1.35.0
minor
| ||
1.34.0
minor
| ||
1.33.0
minor
| ||
1.32.0
minor
| ||
1.31.0
minor
| ||
1.30.0
minor
| ||
1.29.2
patch
| ||
1.29.1
patch
| ||
1.29.0
minor
| ||
1.28.2
patch
| ||
1.28.1
patch
| ||
1.28.0
minor
| ||
1.27.1
patch
| ||
1.27.0
minor
| ||
1.26.0
minor
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.25.0
minor
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.24.1
patch
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.24.0
minor
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.23.2
patch
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.23.1
patch
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.23.0
minor
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.22.3
patch
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.22.2
patch
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.22.1
patch
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.22.0
minor
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.21.1
patch
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.21.0
minor
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.20.1
patch
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.20.0
minor
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.19.2
patch
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.19.1
patch
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.19.0
minor
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.18.1
patch
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.18.0
minor
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.17.1
patch
1 CVE
CVE-2025-51427
PYSEC-2026-2663
GHSA-fhhq-h4hg-549x
Jul 13, 2026
ModelScope is vulnerable to arbitrary code injection via a crafted module
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module']. Affected versions
1.0.4
1.1.1
1.1.3
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0
+ 51 more Show less
1.15.0
1.16.0
1.16.1
1.17.0
1.17.1
1.18.0
1.18.1
1.19.0
1.19.1
1.19.2
1.2.0
1.2.1
1.20.0
1.20.1
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.23.1
1.23.2
1.24.0
1.24.1
1.25.0
1.26.0
1.3.0
1.3.1
1.3.2
1.4.0
1.4.1
1.4.2
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
1.8.0rc0
1.8.1
1.8.3
1.8.4
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Fixed in
1.27.0
References
Updated Jul 13, 2026 · Source: OSV.dev |