YAML Metadata Warning:empty or missing yaml metadata in repo card

Check out the documentation for more information.

PoC - modelaudit NeMo checkpoint extension-coverage gap (BL-0106)

Coordinated disclosure PoC for huntr (Protect AI MFV). Benign only.

  • Scanner: modelaudit==0.2.49 (nemo_scanner.py). Format: NeMo (.nemo, a tar bundle).
  • modelaudit scan bypass_bin.nemo -> Clean/exit 0: an unsafe pickle stored as model_weights.bin (or .dill/.joblib) inside the .nemo is NOT scanned, because nemo_scanner only opcode-scans members ending in {.ckpt,.pt,.pth,.pkl,.pickle} (line 1163). control_ckpt.nemo is the identical payload named .ckpt -> CRITICAL (CVE-2025-23249). Renaming bypass_bin.nemo -> .tar also flips it to CRITICAL (isolates the .nemo gate).
  • Benign: the embedded pickle only touches a marker file on load. No destructive action.

Files: bypass_bin/dill/joblib.nemo (bypass), control_ckpt.nemo (fires). Full report in huntr submission.

Downloads last month
18
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support