Security Advisory
CVE-2024-37065
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code on an end users system when loaded.