Downloads · 30 days
0
romandaripper/modelscan-numpy2-failopen-npy-poc
modelscan-numpy2-failopen-npy-poc is a machine learning model from romandaripper. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as apache-2.0.
Proof-of-concept for a huntr Model File Vulnerabilities (MFV) report against modelscan 0.8.8.
Downloads · 30 days
0
Access
Public
Updated Jul 30, 2026
Repo size
318 B
Likes
0
Public
Click a slice to open those files.
.md2.1 KB · 46%
From the Hugging Face model README
.npy under numpy >= 2Proof-of-concept for a huntr Model File Vulnerabilities (MFV) report against
modelscan 0.8.8.
Payload is deliberately harmless: it runs echo NPY_EXEC_OK. No network access, no deletion,
nothing written outside the working directory.
modelscan/tools/picklescanner.py:234 calls a private numpy API:
np.lib.format._check_version(version) # type: ignore[attr-defined]
numpy 2.0 removed _check_version. Under numpy >= 2 the call raises
AttributeError, the .npy scanner aborts — and modelscan still prints an affirmative
clean verdict. The error is relegated to a secondary Errors section and the skipped
count is hidden behind --show-skipped.
pip install modelscan today resolves numpy 2.x by default, so a default install
returns a clean verdict for any malicious .npy.
| numpy | modelscan 0.8.8 verdict |
|---|---|
| 2.5.1 | No issues found! 🎉 + Errors: module 'numpy.lib.format' has no attribute '_check_version' + Total skipped: 1 |
| 1.26.4 | CRITICAL: 1 — Use of unsafe operator 'system' from module 'posix' |
python -m venv v2 && ./v2/bin/pip install modelscan==0.8.8 numpy==2.5.1
./v2/bin/python generate_poc.py
./v2/bin/modelscan -p poc_object_array.npy # "No issues found!" <-- fails open
python -m venv v1 && ./v1/bin/pip install modelscan==0.8.8 numpy==1.26.4
./v1/bin/modelscan -p poc_object_array.npy # CRITICAL: unsafe operator 'system'
np.lib.format._check_version; gate on numpy.__version__ or
drop the check (_read_array_header already validates the version).Cyfra Tech Solutions (Roman Arce Bran), Costa Rica.