Modelscan Bypass: profile.run() β RCE
β οΈ SECURITY RESEARCH ONLY
Vulnerability
profile.run() internally calls exec() on its code string argument. The profile module is not in modelscan's blocklist.
Impact
- Type: RCE β Full arbitrary code execution
- Modelscan result: "No issues found"
- Single function call, no chaining needed
Responsible Disclosure
Gated access. Reported to ProtectAI via Huntr.
Inference Providers NEW
This model isn't deployed by any Inference Provider. π Ask for provider support