vellaveto/gguf-scanner-bypass-poc
059
GGUF Scanner Bypass PoC — Security Research Artifacts
WARNING: These are intentionally malformed/malicious model files for authorized security research. DO NOT load them outside sandboxed environments.
Purpose
Integer overflow, string overflow, negative dimensions, and path traversal in GGUF headers bypass modelscan 0.8.8 (6/6 MISSED). These target C parsers (llama.cpp, ggml) and can cause heap corruption, OOB reads, or DoS.
Responsible disclosure artifacts for the huntr MFV program.
Scanner Results (2026-03-20)
modelscan 0.8.8: ALL payloads MISSED.
Format
GGUF ($4,000 MFV bounty on huntr)
Researcher
vellaveto
