CVE-2025-51427

7.3

ModelScope · ModelScope

A vulnerability exists in ModelScope that may allow for unauthorized actions, as indicated by recent community disclosures.

Executive summary

ModelScope is affected by a security vulnerability that could potentially allow for unauthorized impacts, requiring immediate attention from administrators.

Vulnerability

The vulnerability is characterized by an unauthenticated attack vector (AV:N/AC:L/PR:N/UI:N), allowing for potential impact to confidentiality, integrity, and availability.

Business impact

With a CVSS score of 7.3, this vulnerability poses a high risk to environments utilizing ModelScope for machine learning workflows. Potential impacts include unauthorized manipulation of model data or disruption of services, which could compromise the integrity of AI-driven projects and business processes.

Remediation

Immediate Action: Review the project's official GitHub repository and issues page (linked in references) to identify and apply the latest security patches or configuration hardening steps.

Proactive Monitoring: Monitor system logs for anomalous API calls or unauthorized access attempts against the ModelScope environment.

Compensating Controls: Implement network-level access controls and Web Application Firewalls (WAF) to restrict exposure of the ModelScope interface to untrusted networks.

Exploitation status

Public Exploit Available: No (CISA SSVC assessment identifies a PoC exists, but no weaponized exploit is confirmed).

Analyst recommendation

Given the availability of a proof-of-concept and the high degree of exploitability, administrators should treat this as a priority. Ensure that the ModelScope instance is updated to the latest available version and that access is strictly controlled.

More ModelScope CVEs