Downloads · 30 days
0
celvexgroup/modelaudit-mlflow-models-from-code-poc
modelaudit-mlflow-models-from-code-poc is a machine learning model from celvexgroup. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
Coordinated disclosure PoC for huntr (Protect AI MFV). Benign only.
Downloads · 30 days
0
Access
Public
Updated Jul 18, 2026
Repo size
74 B
Likes
0
Public
Click a slice to open those files.
Other2.4 KB · 54%
From the Hugging Face model README
Coordinated disclosure PoC for huntr (Protect AI MFV). Benign only.
modelaudit scan evil_mfc_model/ -> 'Clean' / NO ISSUES FOUND / exit 0, but mlflow.pyfunc.load_model('evil_mfc_model') imports+executes evil_script.py at load time (RCE). MLflow models-from-code persists a model as a plain .py entrypoint + an MLmodel YAML manifest with NO pickle; modelaudit classifies the .py (and the MLmodel) as 'unknown format' and skips them (core.py:7005-7008), and never follows the manifest's model_code_path. benign_mfc_model/ is the same shape with no payload (also Clean = the miss is genuine); pickle_positive_control/model.pkl fires CRITICAL (posix.system), proving the detector is live.Files: evil_mfc_model/ (MLmodel + evil_script.py; scans Clean, RCE on load), benign_mfc_model/ (control), pickle_positive_control/model.pkl (fires). Full report in huntr submission.