{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amodelscopemodelscope/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:modelscope:modelscope:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-84202"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ModelScope"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","vulnerability","supply-chain"],"_cs_type":"advisory","_cs_vendors":["ModelScope"],"content_html":"\u003cp\u003eModelScope is a machine learning model library that, in affected versions, improperly handles model configuration files. The vulnerability arises from the use of PyYAML's \u003ccode\u003eyaml.Loader\u003c/code\u003e (often referred to as the unsafe loader) to deserialize configuration files. By crafting a model repository that includes a maliciously formatted configuration file containing specific Python object construction tags (e.g., \u003ccode\u003e!!python/object/apply\u003c/code\u003e), an attacker can trigger arbitrary code execution within the context of the user or system loading the model. This impact is significant for organizations relying on ModelScope to pull and execute machine learning models from external or potentially untrusted repositories, as the mere act of loading a configuration file becomes a primary vector for host compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to execute arbitrary code with the privileges of the process running the ModelScope framework. This can lead to full host compromise, exfiltration of sensitive data, or lateral movement within the network. Users of the library who automatically ingest models from public or unvetted sources are at the highest risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the ModelScope library to the latest version, which removes the use of the unsafe \u003ccode\u003eyaml.Loader\u003c/code\u003e in favor of \u003ccode\u003eyaml.SafeLoader\u003c/code\u003e for configuration parsing.\u003c/li\u003e\n\u003cli\u003eAudit all model repository sources currently in use to ensure they originate from trusted entities only.\u003c/li\u003e\n\u003cli\u003eImplement strict sandboxing for any machine learning processes that ingest configuration data from unverified model repositories.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T17:07:13Z","date_published":"2026-09-01T17:07:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-modelscope-rce/","summary":"ModelScope insecurely utilizes the unsafe yaml.Loader to parse model configuration files, allowing an attacker to achieve arbitrary code execution by supplying a poisoned repository containing malicious Python object construction tags.","title":"Arbitrary Code Execution in ModelScope via Insecure PyYAML Parsing","url":"https://feed.craftedsignal.io/briefs/2026-09-modelscope-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:modelscope:modelscope:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}