Gated security proof-of-concept

This repository is publicly accessible, but you have to accept the conditions to access its files and content.

This repository contains a coordinated-disclosure security proof-of-concept for a trust_remote_code consent issue in the GLiNER model loader. It contains no user data and no network callback beyond normal Hub/model load. Access is restricted to the affected maintainers and the huntr / ProtectAI triage team for verification and remediation only.

Log in or Sign Up to review the conditions and access this model content.

GLiNER loader โ€” forced trust_remote_code consent-bypass PoC (gated)

This is a security research proof-of-concept for the huntr Model File Formats program (format json). It demonstrates that stock GLiNER.from_pretrained can execute attacker code from a model package without any user trust_remote_code opt-in.

The payload is a minimal GLiNER-shaped model directory used only to show the consent defect. There is no weaponization beyond a local marker file, no user data, and no outbound exfil.

  • Class: consent-bypass / unsafe remote code load (CWE-94 / CWE-829)
  • Affected: GLiNER (PyPI gliner, urchade/GLiNER) encoder/decoder HF load path
  • Disclosure: coordinated via huntr MFF

Full technical details and regenerator are in the gated files / huntr report.

Contact: security researcher mrw0r57 (huntr: ssjcorpsec).

Downloads last month
-
Safetensors
Model size
1 params
Tensor type
F32
ยท
Inference Providers NEW
This model isn't deployed by any Inference Provider. ๐Ÿ™‹ Ask for provider support