© 2025-2026 PySpect
First version without a known vulnerability: 0.13.0
SKOPS Card.get_model happily allows arbitrary code execution
Fixed in: 0.13.0
Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
Fixed in: 0.12.0
Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
Fixed in: 0.12.0
Skops unsafe deserialization