CVE-2025-54886 | skops up to 0.12.x Card.get_model deserialization
A vulnerability classified as problematic has been found in skops up to 0.12.x. This affects the function Card.get_model. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2025-54886. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.