REDHAT-BUG-2479894: High severity modelscope ModelScope vulnerability
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (deymini.yaml) under the key ['nnet']['module'].
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ModelScopeto a version that resolves this vulnerability.Fixed in 1.25.0 - Compensating control
Review and restrict the value of the configuration file dey_mini.yaml at key ['nnet']['module'] to trusted module entries only, since crafted modules listed there can enable arbitrary code execution.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2479894?
The severity of REDHAT-BUG-2479894 is high with a score of 7.
How do I fix REDHAT-BUG-2479894?
To fix REDHAT-BUG-2479894, ensure that you do not use crafted modules in the configuration file and adhere to secure coding practices.
What type of attack does REDHAT-BUG-2479894 enable?
REDHAT-BUG-2479894 enables attackers to execute arbitrary code through crafted modules.
Which software is affected by REDHAT-BUG-2479894?
The software affected by REDHAT-BUG-2479894 is ModelScope version 1.25.0.
When was REDHAT-BUG-2479894 published?
REDHAT-BUG-2479894 was published on May 19, 2026.