Downloads · 30 days
0
TESTforge42/scanner-bypass-genops-poc
scanner-bypass-genops-poc is a machine learning model from TESTforge42. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
This is a benign security-research proof-of-concept for a coordinated vulnerability disclosure to huntr's Model File Format program. It is not malware.
Downloads · 30 days
0
Access
Public
Updated Jul 24, 2026
Repo size
89 B
Likes
1
Public
Click a slice to open those files.
.md1.7 KB · 51%
From the Hugging Face model README
This is a benign security-research proof-of-concept for a coordinated vulnerability disclosure to huntr's Model File Format program. It is not malware.
model.pt is an 89-byte PyTorch/pickle file that demonstrates a parser desync between the static
model scanners (picklescan, ModelScan — both walk pickles with pickletools.genops, base-10 int parsing)
and the real C unpickler (_pickle, base-0 int parsing). The 6-byte INT opcode I0x10\n makes the
scanners' opcode walk abort before the payload, so both scanners report the file clean, while
torch.load() executes the payload.
The payload is intentionally harmless: it writes a marker file to the system temp directory
(NOMOS_SCANNER_BYPASS) to prove code execution. No data is exfiltrated, nothing is destroyed, there is
no network activity and no self-propagation.
pip install picklescan==1.0.5 modelscan==0.8.8 torch
picklescan -p model.pt # -> exit 0, PRISTINE (0 dangerous globals)
modelscan scan model.pt # -> "No issues found"
python -c "import torch; torch.load('model.pt', weights_only=False)" # -> marker written = code executed
genops-based walkers must fail closed (UNSAFE) on any parse
abort, and align INT opcode parsing with the C unpickler (or reject non-decimal INT args).Full write-up: see the disclosure package accompanying this PoC.