romandaripper's picture
Upload README.md with huggingface_hub
fd8ef7f verified
|
Raw
History Blame Contribute Delete
2.13 kB
---
license: apache-2.0
tags: [security, proof-of-concept, modelscan]
---
# PoC β€” modelscan fails **open** on `.npy` under numpy >= 2
Proof-of-concept for a **huntr Model File Vulnerabilities (MFV)** report against
[`modelscan`](https://github.com/protectai/modelscan) **0.8.8**.
Payload is deliberately harmless: it runs `echo NPY_EXEC_OK`. No network access, no deletion,
nothing written outside the working directory.
## The issue
`modelscan/tools/picklescanner.py:234` calls a **private numpy API**:
```python
np.lib.format._check_version(version) # type: ignore[attr-defined]
```
`numpy` **2.0 removed `_check_version`**. Under numpy >= 2 the call raises
`AttributeError`, the `.npy` scanner aborts β€” and modelscan still prints an affirmative
clean verdict. The error is relegated to a secondary `Errors` section and the skipped
count is hidden behind `--show-skipped`.
`pip install modelscan` today resolves numpy 2.x by default, so a default install
returns a clean verdict for **any** malicious `.npy`.
## Measured differential β€” identical file, only numpy differs
| numpy | modelscan 0.8.8 verdict |
|---|---|
| **2.5.1** | ` No issues found! πŸŽ‰` + `Errors: module 'numpy.lib.format' has no attribute '_check_version'` + `Total skipped: 1` |
| **1.26.4** | `CRITICAL: 1` β€” *Use of unsafe operator 'system' from module 'posix'* |
## Reproduce
```bash
python -m venv v2 && ./v2/bin/pip install modelscan==0.8.8 numpy==2.5.1
./v2/bin/python generate_poc.py
./v2/bin/modelscan -p poc_object_array.npy # "No issues found!" <-- fails open
python -m venv v1 && ./v1/bin/pip install modelscan==0.8.8 numpy==1.26.4
./v1/bin/modelscan -p poc_object_array.npy # CRITICAL: unsafe operator 'system'
```
## Suggested fix
- Stop calling the private `np.lib.format._check_version`; gate on `numpy.__version__` or
drop the check (`_read_array_header` already validates the version).
- **Fail closed:** a scanner that raised must not yield an affirmative "No issues found"
summary. Surface aborted scans in the main verdict.
## Attribution
Cyfra Tech Solutions (Roman Arce Bran), Costa Rica.