YAML Metadata Warning:empty or missing yaml metadata in repo card

Check out the documentation for more information.

PMML XXE/SSRF PoC

Malicious PMML model files that exploit XXE in pypmml/pmml4s.

Files

  • ssrf_poc.pmml โ€” Triggers SSRF (HTTP request to attacker server)
  • file_read_poc.pmml โ€” Reads local files via file:// protocol
  • poc.py โ€” Automated PoC script

Usage

pip install pypmml
python poc.py

Root Cause

pmml4s/src/main/scala/org/pmml4s/xml/pull.scala line 91: XMLInputFactory.newFactory without disabling external entities.

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. ๐Ÿ™‹ Ask for provider support