Downloads · 30 days
0
MarcOrtiz21/joblib-ndarray-sidecar-bypass-poc
joblib-ndarray-sidecar-bypass-poc is a machine learning model from MarcOrtiz21. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
Security research PoC for responsible disclosure through Huntr's Model File Vulnerability program.
Downloads · 30 days
0
Access
Public
Updated May 18, 2026
Repo size
142 B
Likes
0
Public
Click a slice to open those files.
.md1.9 KB · 38%
From the Hugging Face model README
Security research PoC for responsible disclosure through Huntr's Model File Vulnerability program.
This repository demonstrates a scanner-bypass pattern for .joblib artifacts:
model.joblib contains a legacy joblib.numpy_pickle_compat.NDArrayWrapper.weights.weights.weights.weights is a valid NumPy object-array file with an unsupported extension.joblib.load("model.joblib") resolves and loads the sidecar with allow_pickle=True.The payload is benign. Loading the model writes a marker file at /tmp/joblib_mfv_marker.txt.
3.12.13joblib==1.5.3modelscan==0.8.8picklescan==1.0.4numpy==2.4.5python -m venv .venv
. .venv/bin/activate
pip install -r requirements.txt
rm -f /tmp/joblib_mfv_marker.txt
python reproduce.py
test -f /tmp/joblib_mfv_marker.txt && echo "marker created"
modelscan -p . -r json --show-skipped
picklescan -p . -g
Expected scanner behavior:
model.joblib, skips weights.weights as unsupported, and reports 0 issues.0 infected files and 0 dangerous globals for this artifact.Expected load behavior:
joblib.load("model.joblib") creates /tmp/joblib_mfv_marker.txt.The dangerous pickle stream is not stored in the main .joblib file. It is stored in a sidecar file whose filename is controlled by the legacy Joblib wrapper. Scanners that only inspect the wrapper stream, or only scan NumPy files by extension, miss the payload that Joblib later loads.
This is distinct from generic pickle/joblib deserialization and from already-public compressed-joblib or inline NumPy object-array bypasses.