| license: mit | |
| # ModelScan Nested Pickle Bypass | |
| A novel technique that hides malicious pickled objects inside **opaque BINBYTES** blocks. ModelScan only inspects outer-layer GLOBAL opcodes, so the inner pickle (containing os.system, subprocess, etc.) is never scanned. | |
| ## Bypass GLOBALs (what ModelScan sees) | |
| - `importlib.import_module` — NOT in unsafe_globals | |
| - `operator.methodcaller` — NOT in unsafe_globals | |
| ## Hidden GLOBALs (inside BINBYTES, never inspected) | |
| - `os.system` — full RCE | |
| - (or any other blocked module) | |
| ## Verification | |
| ```bash | |
| modelscan -p exploit_nested.joblib | |
| # -> "No issues found!" | |
| ``` | |
| ## PoC Size | |
| 177 bytes | |
| ## Format | |
| Joblib (pickle-based, $4,000 MFV tier) | |