ModelScan Bypass PoC โ xmlrpc.client.ServerProxy SSRF
Security research โ responsible disclosure via Huntr MFV program.
This model file demonstrates a bypass of ProtectAI's modelscan scanner.
The pickle payload uses xmlrpc.client.ServerProxy to establish outbound
XML-RPC connections to attacker-controlled servers.
DO NOT load these files with pickle.load() outside a sandbox.
Inference Providers NEW
This model isn't deployed by any Inference Provider. ๐ Ask for provider support