rez0's picture
Upload folder using huggingface_hub
86d0fa6 verified

msgpack-numpy Hidden pickle.loads() RCE

Security research for huntr. msgpack_numpy.decode() calls pickle.loads() on object dtype arrays. No scanner checks .msgpack files.