Keras
xiaoyaoes's picture
Fix PoC: add compile_config loss __lambda__ with RCE marshal payload
8dbc1a4
|
Raw
History Blame Contribute Delete
802 Bytes
---
license: mit
---
# Keras compile_config Lambda RCE PoC
ModelScan bypass via compile_config.loss.__lambda__
## Vulnerability
Keras v3 models can specify a loss function of type `__lambda__`. When loaded with `safe_mode=False`, Keras `eval()`'s the lambda source string, allowing arbitrary code execution.
ModelScan checks for `class_name: "Lambda"` (capital L, referring to the Keras Lambda layer) but does not scan `class_name: "__lambda__"` (referring to the loss function type). This creates a complete bypass.
## Usage
```bash
pip install keras tensorflow
python3 exploit.py
```
## Files
- `evil_model.keras` — Malicious model with __lambda__ loss containing RCE payload
- `exploit.py` — Loader script
## Impact
CVSS 9.8. Supply chain attack via HuggingFace/any model repository.