CVE-2025-51427
7.3ModelScope · ModelScope
A vulnerability exists in ModelScope that may allow for unauthorized actions, as indicated by recent community disclosures.
Executive summary
ModelScope is affected by a security vulnerability that could potentially allow for unauthorized impacts, requiring immediate attention from administrators.
Vulnerability
The vulnerability is characterized by an unauthenticated attack vector (AV:N/AC:L/PR:N/UI:N), allowing for potential impact to confidentiality, integrity, and availability.
Business impact
With a CVSS score of 7.3, this vulnerability poses a high risk to environments utilizing ModelScope for machine learning workflows. Potential impacts include unauthorized manipulation of model data or disruption of services, which could compromise the integrity of AI-driven projects and business processes.
Remediation
Immediate Action: Review the project's official GitHub repository and issues page (linked in references) to identify and apply the latest security patches or configuration hardening steps.
Proactive Monitoring: Monitor system logs for anomalous API calls or unauthorized access attempts against the ModelScope environment.
Compensating Controls: Implement network-level access controls and Web Application Firewalls (WAF) to restrict exposure of the ModelScope interface to untrusted networks.
Exploitation status
Public Exploit Available: No (CISA SSVC assessment identifies a PoC exists, but no weaponized exploit is confirmed).
Analyst recommendation
Given the availability of a proof-of-concept and the high degree of exploitability, administrators should treat this as a priority. Ensure that the ModelScope instance is updated to the latest available version and that access is strictly controlled.