TESTforge42's picture
Upload README.md with huggingface_hub
cbcb4c0 verified
|
Raw
History Blame Contribute Delete
529 Bytes

Security-research PoC — ModelScan bypass via profile.run gadget (benign, huntr disclosure)

model.pkl calls profile.run(code) at unpickle — a stdlib profiler whose .run() executes arbitrary code via exec(). ModelScan's denylist omits the profilers, so it reports "No issues found"; the payload writes a benign marker to temp. Reproduce: modelscan scan model.pkl (clean) then python -c "import pickle;pickle.load(open('model.pkl','rb'))" (marker written = exec). Fix: add profile/cProfile/pstats to the denylist.