rez0's picture
Upload folder using huggingface_hub
86d0fa6 verified
# msgpack-numpy Hidden pickle.loads() RCE
Security research for huntr.
msgpack_numpy.decode() calls pickle.loads() on object dtype arrays.
No scanner checks .msgpack files.