PoC: Code Execution via Unsafe Keras Deserialization
This .keras model demonstrates arbitrary code execution during loading when safe_mode=False is used — a common misconfiguration in ML pipelines.
⚠️ For research and validation only. Do not load in production.
Payload Behavior
On load, the model executes:
echo 'SCANNER-BUYPass' > /tmp/pwned
- Downloads last month
- -
Inference Providers
NEW
This model isn't deployed by any Inference Provider.
🙋
Ask for provider support