Security PoC (MLflow statsmodels pickle safety bypass)
This is a security proof-of-concept model, NOT a real ML model.
This MLflow statsmodels-flavor model demonstrates that MLFLOW_ALLOW_PICKLE_DESERIALIZATION=false is silently bypassed by the statsmodels flavor. When loaded via mlflow.pyfunc.load_model(), the model executes a benign marker-write payload proving arbitrary code execution.
Vulnerability
MLflow documents MLFLOW_ALLOW_PICKLE_DESERIALIZATION as a global protection. When set to false, loading any pickle-based model should raise an error. The statsmodels flavor (mlflow/statsmodels/__init__.py) never consults this toggle -- it calls smio.load_pickle() unconditionally.
Reproduction
pip install mlflow==3.14.0 statsmodels
export MLFLOW_ALLOW_PICKLE_DESERIALIZATION=false
python -c "import mlflow; mlflow.pyfunc.load_model('<this-repo-path>')"
# marker file written to /tmp/aisc0005_mfv_pwned
Impact
A deployer who hardened via =false still gets arbitrary code execution when a statsmodels-flavor model is loaded, including via the pyfunc scoring server.
Responsible disclosure
Submitted via huntr.com Model File Format program.