metadata
license: mit
ModelScan Nested Pickle Bypass
A novel technique that hides malicious pickled objects inside opaque BINBYTES blocks. ModelScan only inspects outer-layer GLOBAL opcodes, so the inner pickle (containing os.system, subprocess, etc.) is never scanned.
Bypass GLOBALs (what ModelScan sees)
importlib.import_module— NOT in unsafe_globalsoperator.methodcaller— NOT in unsafe_globals
Hidden GLOBALs (inside BINBYTES, never inspected)
os.system— full RCE- (or any other blocked module)
Verification
modelscan -p exploit_nested.joblib
# -> "No issues found!"
PoC Size
177 bytes
Format
Joblib (pickle-based, $4,000 MFV tier)