Hugging Face
Models
Datasets
Spaces
Buckets
new
Docs
Enterprise
Pricing
Website
Tasks
HuggingChat
Collections
Languages
Organizations
Community
Blog
Posts
Daily Papers
Hardware
Learn
Discord
Forum
GitHub
Solutions
Team & Enterprise
Hugging Face PRO
Enterprise Support
Inference Providers
Inference Endpoints
Storage Buckets
Log In
Sign Up
ChristianTeroerde
/
modelscan-legacy-multipickle-poc
like
0
security
proof-of-concept
modelscan
License:
apache-2.0
Model card
Files
Files and versions
xet
Community
Copy to bucket
new
main
modelscan-legacy-multipickle-poc
5.3 kB
Ctrl+K
Ctrl+K
1 contributor
History:
4 commits
This model has 1 file scanned as unsafe.
Show
files
ChristianTeroerde
Upload build_and_verify.py with huggingface_hub
2c7cca1
verified
2 months ago
.gitattributes
Safe
1.52 kB
initial commit
2 months ago
README.md
1.84 kB
PoC: modelscan legacy multi-pickle bypass (benign marker)
2 months ago
build_and_verify.py
1.33 kB
Upload build_and_verify.py with huggingface_hub
2 months ago
model.pt
Unsafe
pickle
Detected Pickle imports (4)
"torch._utils._rebuild_tensor_v2"
,
"torch.FloatStorage"
,
"posix.system"
,
"collections.OrderedDict"
How to fix it?
620 Bytes
xet
legacy non-zip PyTorch checkpoint (modelscan reports clean, executes on load)
2 months ago