modelscan NumPy fail-open PoC (security research)

Benign PoC for a huntr Model-File-Vulnerability submission. On numpy >= 2.0, modelscan's NumPy scanner calls removed private APIs (numpy.lib.format._check_version / _read_array_header), so scanning any .npy/.npz raises an error that modelscan treats as a skip -> reported 'No issues found'. poc_model.npy is an object-array whose reduce runs a command at np.load(allow_pickle=True) time (benign: writes /tmp/modelscan_npy_poc.txt).

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support