Security Research PoC - Joblib Scanner Bypass
This repository contains a proof-of-concept for a model file vulnerability disclosure via huntr.com.
WARNING: The .joblib file in this repository contains a malicious payload. Do NOT load it outside of a sandboxed environment.
Vulnerability
A novel pickle deserialization gadget using dataclasses._create_fn() achieves arbitrary code execution when loaded via joblib.load(), while bypassing all model file scanners (modelscan, picklescan, fickling).
Responsible Disclosure
This PoC is gated and shared only with ProtectAI for review.
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support