How to use from
Docker Model Runner
# Gated model: Login with a HF token with gated access permission
hf auth login
docker model run hf.co/emaadbs/modelaudit-gguf-ssti-poc
Quick Links

You need to agree to share your contact information to access this model

This repository is publicly accessible, but you have to accept the conditions to access its files and content.

This repository contains a deliberately malicious model file submitted as a security proof-of-concept to the Protect AI / huntr Model File Vulnerability program. Access is granted only to the program's automated scanner and triage team. Do not load this file outside an isolated sandbox.

Log in or Sign Up to review the conditions and access this model content.

PoC β€” modelaudit GGUF chat-template SSTI scanner evasion (DO NOT USE)

This repo exists only as a security proof-of-concept for a huntr Model File Vulnerability disclosure. The single artifact, poc.gguf, is a malicious GGUF model whose tokenizer.chat_template is crafted to:

  1. pass modelaudit (Protect AI Guardian / HF model scan) as CLEAN β€” 0 findings, while
  2. executing an arbitrary OS command when the chat template is rendered by an unsandboxed Jinja2 renderer (the CVE-2024-34359 class).

The embedded command in the published PoC is a harmless system('id') / touch <tmp marker> β€” it demonstrates execution without doing damage.

  • poc.gguf sha256: 96bb3bd496503fdf6a01a9d0f230612869f7479bdcffb8cccaf20d33734c44f9
  • Payload (in tokenizer.chat_template): {% if messages %}{{ lipsum['__glo'~'bals__']['o'~'s'].system('id') }}{% endif %}

Full root-cause, decomposition, reproduction, and remediation are in the huntr disclosure report. Do not load this model outside an isolated sandbox.

Downloads last month
2
GGUF
Model size
0 params
Architecture
llama
Hardware compatibility
Log In to add your hardware

We're not able to determine the quantization variants.

Inference Providers NEW
This model isn't deployed by any Inference Provider. πŸ™‹ Ask for provider support