YAML Metadata Warning: empty or missing yaml metadata in repo card
Check out the documentation for more information.
MONAI Bundle Config ACE PoC
Security research model bundle for huntr.com Model Format Vulnerability program.
DO NOT LOAD THIS BUNDLE โ it contains a crafted MONAI bundle config that achieves arbitrary code execution via _target_ โ pydoc.locate().
Details
_target_values in config JSON resolved viapydoc.locate()with zero allowlist- Achieves arbitrary code execution via
monai.bundle.load()โcreate_workflow()โinitialize() - Works even with
MONAI_EVAL_EXPR=0 - Same vulnerability class as NeMo CVE-2025-23304
Inference Providers NEW
This model isn't deployed by any Inference Provider. ๐ Ask for provider support