YAML Metadata Warning:empty or missing yaml metadata in repo card
Check out the documentation for more information.
JAX Scanner Bypass PoC
Vulnerability Summary
Format: JAX (.jax)
Scanner Bypass: modelscan 0.8.7 + picklescan 1.0.1 (DUAL BYPASS)
Impact: Arbitrary Code Execution via malicious model file
Reproduction
modelscan -p malicious_model.jax
picklescan -p malicious_model.jax
python3 -c "import joblib; joblib.load('malicious_model.jax')"
Scanner Results
modelscan 0.8.7: No issues found (BYPASS) picklescan 1.0.1: No issues found (BYPASS) joblib.load(): Executes eval - ACE CONFIRMED
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support