Downloads · 30 days
0
xiaoyaoes/modelscan-trace-bypass-poc
modelscan-trace-bypass-poc is a machine learning model from xiaoyaoes. Use it for the machine learning task on the model card, and read the license before you ship it in a product. It is set up for generic.
trace module is not in any ModelScan blocklist level (CRITICAL/HIGH/MEDIUM). trace.Trace.run() internally calls exec() on the provided code string.
Downloads · 30 days
0
Access
Public
Updated Jun 18, 2026
Repo size
474 B
Likes
0
Public
Click a slice to open those files.
Other1.5 KB · 60%
From the Hugging Face model README
trace.Trace.run() + operator.methodcaller()trace module is not in any ModelScan blocklist level (CRITICAL/HIGH/MEDIUM).
trace.Trace.run() internally calls exec() on the provided code string.
Bypass chain:
operator.methodcaller("run", CODE)(trace.Trace(0, 0))
-> trace.Trace(0, 0).run(CODE)
-> exec(CODE)
-> REMOTE CODE EXECUTION
Size: 127 bytes (.pkl) / 347 bytes (.joblib)