F-MFV-005: ModelScan misses llvmlite native-library loading in Joblib model files
This repository contains a gated proof-of-concept model artifact for a Huntr Model File Vulnerability submission.
Warning: do not load this artifact outside an isolated test environment. The payload is intentionally harmless and writes only local marker files during controlled reproduction, but it demonstrates a model-load execution path.
Target
- Finding:
F-MFV-005 - Target: Joblib / ModelScan
- Scanner: ModelScan
0.8.8
Summary
The Joblib artifact embeds a harmless shared library and loads it through llvmlite.binding.load_library_permanently during model load while ModelScan 0.8.8 reports zero issues.
Files
llvmlite_library.joblib- SHA256:
f9cec4cc4c3f01bdfd5c98cd95245c99007d66458e496930244d5de8c7abc63c
- SHA256:
Access
This public repository is gated with manual access review for Huntr MFV triage. protectai-bot has been granted access.
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support