Kanisia's picture
Upload 6 files
0c87073 verified
|
Raw
History Blame Contribute Delete
626 Bytes

ModelScan pickle SourceFileLoader bypass PoC

This PoC demonstrates a pickle payload that reaches importlib.machinery.SourceFileLoader.load_module() during deserialization while ModelScan reports 0 issues.

Files:

  • bypass_sourcefileloader.pkl - bypass payload
  • control_os_system.pkl - control payload that ModelScan detects as CRITICAL
  • poc_side_effect.py - benign local module used by the verification script
  • verify_pickle_reaches_sourcefileloader.py - verifies that unpickling reaches SourceFileLoader and executes the local module
  • scan-result.txt - local ModelScan and verification results