YAML Metadata Warning:empty or missing yaml metadata in repo card

Check out the documentation for more information.

PoC - modelscan skips raw pickle in .bin/.pt members as 'Invalid magic number' (BL-0117)

Coordinated disclosure PoC for huntr (Protect AI MFV). Benign only.

  • Scanner: modelscan==0.8.8 (picklescanner.py). Format: DL4J (.zip) / any bundle with a .bin/.pt/.pth/.ckpt member.
  • modelscan -p dl4j_bypass.zip -> 'No issues found', exit 0: a raw unsafe-op pickle carried in a PyTorch-extension member (DL4J's coefficients.bin) is skipped by scan_pytorch as 'Invalid magic number' and never opcode-scanned. dl4j_control.zip (byte-identical, member renamed coefficients.pkl) -> CRITICAL exit 1 (positive control). standalone_payload.bin vs .pkl show the same split.
  • Load-side kicker: real torch.load('standalone_payload.bin', weights_only=False) raises 'Invalid magic number' BUT the payload already executed during the pre-check pickle load (CWE-436): the same magic-check modelscan uses to SKIP, torch uses to execute-then-reject.
  • Root cause: picklescanner.py:254-266 scan_pytorch returns Skipped on magic mismatch; settings.py:82 maps .bin/.pt/.pth/.ckpt to PYTORCH only; the pickle scanner never runs on those extensions. HONEST: shares the scan_pytorch function with BL-0042/0083 (magic-PASSES branch) - this is the distinct magic-FAILS skip branch; huntr may apply a dedup haircut.

Files: dl4j_bypass.zip (bypass), dl4j_control.zip (fires), standalone_payload.bin/.pkl. Full report in huntr submission.

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support