YAML Metadata Warning:empty or missing yaml metadata in repo card
Check out the documentation for more information.
PMML XXE/SSRF PoC
Malicious PMML model files that exploit XXE in pypmml/pmml4s.
Files
ssrf_poc.pmmlโ Triggers SSRF (HTTP request to attacker server)file_read_poc.pmmlโ Reads local files via file:// protocolpoc.pyโ Automated PoC script
Usage
pip install pypmml
python poc.py
Root Cause
pmml4s/src/main/scala/org/pmml4s/xml/pull.scala line 91:
XMLInputFactory.newFactory without disabling external entities.
Inference Providers NEW
This model isn't deployed by any Inference Provider. ๐ Ask for provider support