PoC: Code Execution via Unsafe Keras Deserialization
This .keras model demonstrates arbitrary code execution during loading when safe_mode=False is used — a common misconfiguration in ML pipelines.
⚠️ For research and validation only. Do not load in production.
Payload Behavior
On load, the model executes:
echo 'SCANNER-BUYPass' > /tmp/pwned
- Downloads last month
- -
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support