Downloads · 30 days
0
xiaoyaoes/modelscan-joblib-bypass
modelscan-joblib-bypass is a machine learning model from xiaoyaoes. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as mit.
Three novel techniques that bypass modelscan's pickle scanner in JOBLIB format.
Downloads · 30 days
0
Access
Public
Updated Jun 12, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
Other1.5 KB · 46%
From the Hugging Face model README
Three novel techniques that bypass modelscan's pickle scanner in JOBLIB format.
| # | Technique | Module | unsafe_globals? | Modelscan |
|---|---|---|---|---|
| 1 | PyDLL PyRun_SimpleString | ctypes.PyDLL | NO | No issues |
| 2 | importlib + methodcaller | importlib, operator.methodcaller | NO | No issues |
| 3 | code.InteractiveInterpreter | code.InteractiveInterpreter | NO | No issues |
exploit_pydll.joblib — Uses ctypes.PyDLL(None).PyRun_SimpleString() to execute arbitrary Python via CPython C APIexploit_importlib.joblib — Uses importlib.import_module('os') + operator.methodcaller('system', cmd) for shell RCEexploit_code_interpreter.joblib — Uses code.InteractiveInterpreter().runsource() to execute arbitrary Pythonmodelscan scan -p exploit_pydll.joblib
# -> "No issues found!"
modelscan's unsafe_globals blocklist does NOT include:
ctypes → PyDLL/PyRun_SimpleStringimportlib → import_moduleoperator.methodcaller (only attrgetter is blocked)code → InteractiveInterpreterAll three are standard library modules that can achieve full RCE.