YAML Metadata Warning:empty or missing yaml metadata in repo card
Check out the documentation for more information.
modelscan-bypass-xmlrpc
ProtectAI modelscan Bypass PoC
Module: xmlrpc proxy
Impact: xmlrpc.client.ServerProxy bypass - RPC to attacker server
Scanner: modelscan 0.7.6 (latest on PyPI)
Result: "No issues found" — bypass confirmed
Reproduction
pip install modelscan
modelscan scan -p xmlrpc_proxy.pkl
# Output: "No issues found!"
# But pickle.load() executes the payload
Responsible Disclosure
This PoC is uploaded for responsible disclosure via Huntr MFV program.
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support