Downloads · 30 days
0
aslein1413/poc-mlflow-loader-module-rce
poc-mlflow-loader-module-rce is a machine learning model from aslein1413. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
mlflow.pyfunc.loadmodel() on an untrusted model directory runs code straight from the model, with no pickle involved. The MLmodel file names a loadermodule and a code directory. On load MLflow prepends the model's cod…
Downloads · 30 days
0
Access
Public
Updated Jul 16, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
Other1.7 KB · 44%
From the Hugging Face model README
mlflow.pyfunc.load_model() on an untrusted model directory runs code straight from the
model, with no pickle involved. The MLmodel file names a loader_module and a code
directory. On load MLflow prepends the model's code/ dir to sys.path and imports the
named loader_module, so the module's top-level code runs before you ever call the model.
Here MLmodel points loader_module: evil_loader at code/evil_loader.py, whose import
runs id and drops /tmp/PWNED_mlflow.txt.
model/MLmodel — the model manifest (loader_module + code dir).model/code/evil_loader.py — imported on load; runs id at import time.verify.py — calls load_model("model") and prints the marker.pip install mlflow
python verify.py
# marker after : True
# uid=0(root) gid=0(root) groups=0(root)
Confirmed on a clean python:3.12-slim container with stock mlflow 3.14.0.
There is no pickle here, so a scanner that only looks for pickle opcodes (ModelScan
reports this dir as clean) sees nothing, yet loading the model runs attacker code as the
host process. Any pipeline that loads a user-supplied MLflow model is affected. It fires
on the default load_model call with no flags or environment variables.