Downloads · 30 days
0
TESTforge42/modelscan-bypass-profile-run-poc
modelscan-bypass-profile-run-poc is a machine learning model from TESTforge42. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
model.pkl calls profile.run(code) at unpickle — a stdlib profiler whose .run() executes arbitrary code via exec(). ModelScan's denylist omits the profilers, so it reports "No issues found"; the payload writes a benign…
Downloads · 30 days
0
Access
Public
Updated Jul 24, 2026
Repo size
102 B
Likes
0
Public
Click a slice to open those files.
Other1.5 KB · 71%
From the Hugging Face model README
model.pkl calls profile.run(code) at unpickle — a stdlib profiler whose .run() executes arbitrary code
via exec(). ModelScan's denylist omits the profilers, so it reports "No issues found"; the payload writes a
benign marker to temp. Reproduce: modelscan scan model.pkl (clean) then python -c "import pickle;pickle.load(open('model.pkl','rb'))" (marker written = exec). Fix: add profile/cProfile/pstats to the denylist.