Keras

Keras compile_config Lambda RCE PoC

ModelScan bypass via compile_config.loss.lambda

Vulnerability

Keras v3 models can specify a loss function of type __lambda__. When loaded with safe_mode=False, Keras eval()'s the lambda source string, allowing arbitrary code execution.

ModelScan checks for class_name: "Lambda" (capital L, referring to the Keras Lambda layer) but does not scan class_name: "__lambda__" (referring to the loss function type). This creates a complete bypass.

Usage

pip install keras tensorflow
python3 exploit.py

Files

  • evil_model.keras โ€” Malicious model with lambda loss containing RCE payload
  • exploit.py โ€” Loader script

Impact

CVSS 9.8. Supply chain attack via HuggingFace/any model repository.

Downloads last month
33
Inference Providers NEW
This model isn't deployed by any Inference Provider. ๐Ÿ™‹ Ask for provider support