You need to agree to share your contact information to access this model
This repository is publicly accessible, but you have to accept the conditions to access its files and content.
This repository contains security-research proof-of-concept artifacts: deliberately malicious MLeap bundles (real MLeap-serialized model files) that embed TensorFlow file-system ops which EXECUTE when the bundle is loaded and scored, giving arbitrary file read and arbitrary file write in the loading process (escalating to remote code execution via write-to-execute gadgets). They are provided solely for coordinated vulnerability disclosure and defensive verification, and must be used in an isolated sandbox only. By requesting access you confirm that (1) you will only load these bundles inside an isolated, disposable sandbox, (2) you will not deploy or redistribute them against systems you do not own or operate, and (3) you understand they are bug-triggering artifacts, not usable models. Access is granted to protectai-bot for bounty review and to the vendor for coordinated disclosure.
Log in or Sign Up to review the conditions and access this model content.