{"data":{"ecosystem":"pypi","name":"skops","url":"https://aisecwatch.com/packages/pypi/skops","latestVersion":"0.16.0","firstReleaseAt":"2022-05-04T13:58:51.970Z","repository":"http://github.com/skops-dev/skops","llm":{"exposure":"none","depth":null,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"pypi","name":"numpy","versionSpec":">=1.25.0","scope":"runtime"},{"ecosystem":"pypi","name":"packaging","versionSpec":">=17.0","scope":"runtime"},{"ecosystem":"pypi","name":"prettytable","versionSpec":">=3.9","scope":"runtime"},{"ecosystem":"pypi","name":"rich","versionSpec":">=12","scope":"extra:rich"},{"ecosystem":"pypi","name":"scikit-learn","versionSpec":">=1.2","scope":"runtime"},{"ecosystem":"pypi","name":"scipy","versionSpec":">=1.10.0","scope":"runtime"}],"advisories":[{"id":"9fbbdd08-487d-415b-936c-4844fa31ed75","url":"https://aisecwatch.com/issues/9fbbdd08-487d-415b-936c-4844fa31ed75","cveId":"CVE-2025-54886","title":"CVE-2025-54886: skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and…","headline":"skops Card.get_model arbitrary code execution through joblib fallback","severity":"high","publishedAt":"2025-08-08T05:15:25.120Z","affected":["skops@< 0.13.0 (fixed: 0.13.0)"],"epssScore":0.00218},{"id":"9a1ae049-b274-46cf-a529-8fae591a500a","url":"https://aisecwatch.com/issues/9a1ae049-b274-46cf-a529-8fae591a500a","cveId":"CVE-2025-54413","title":"CVE-2025-54413: skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below…","headline":"skops MethodNode flaw allows code execution when models load","severity":"high","publishedAt":"2025-07-26T08:16:06.793Z","affected":["skops@< 0.12.0 (fixed: 0.12.0)"],"epssScore":0.00144},{"id":"ea9822a1-4828-4de3-b9e2-7549245ad2b8","url":"https://aisecwatch.com/issues/ea9822a1-4828-4de3-b9e2-7549245ad2b8","cveId":"CVE-2025-54412","title":"CVE-2025-54412: skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below…","headline":"skops code execution through OperatorFuncNode operator methods","severity":"high","publishedAt":"2025-07-26T08:16:06.597Z","affected":["skops@< 0.12.0 (fixed: 0.12.0)"],"epssScore":0.00142},{"id":"28fc5eac-b3be-4e88-a2b6-0b5d6cd62918","url":"https://aisecwatch.com/issues/28fc5eac-b3be-4e88-a2b6-0b5d6cd62918","cveId":"CVE-2024-37065","title":"CVE-2024-37065: Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a…","headline":"skops python library deserialization of untrusted data via malicious model","severity":"high","publishedAt":"2024-06-04T12:15:13.507Z","affected":["skops@>= 0.6, <= 0.9"],"epssScore":0.00239}],"checkedAt":"2026-10-09T22:08:39.290Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}