Modelscan Bypass: linecache.getline() β Arbitrary File Read
β οΈ SECURITY RESEARCH ONLY
Vulnerability
linecache.getline(filename, lineno) reads arbitrary files. Not in modelscan's blocklist.
Impact
- Type: Information Disclosure β Read any file accessible to the process
- Can read secrets, config files, private keys
- Modelscan result: "No issues found"
Responsible Disclosure
Gated access. Reported to ProtectAI via Huntr.
Inference Providers NEW
This model isn't deployed by any Inference Provider. π Ask for provider support