Downloads · 30 days
0
ericblackgachara/numpy-npz-poc
numpy-npz-poc is a machine learning model from ericblackgachara. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
Downloads · 30 days
0
Access
Public
Updated May 31, 2026
Repo size
131 KB
Likes
1
Public
Click a slice to open those files.
.pdf131 KB · 92%
From the Hugging Face model README
Loading a crafted 1,328-byte .npz file and accessing one of its members causes
np.load to raise tokenize.TokenError instead of the documented ValueError.
The exception escapes uncaught, crashing any application that catches only ValueError.
| Field | Value |
|---|---|
| Repository | numpy/numpy |
| Entry point | NpzFile.__getitem__ -- numpy/lib/_npyio_impl.py line 178 |
| Affected function | _read_array_header() -- numpy/lib/_format_impl.py line 661 |
| Confirmed version | 2.3.5 (installed), main branch commit b6e8ad8 |
| Python version | 3.12+ |
| Format | .npz (ZIP archive containing malicious .npy member) |
| Platform | huntr.com |
NpzFile.__getitem__ passes each ZIP member to format.read_array -> _read_array_header.
For members with 100+ nested dtype levels, _filter_header raises tokenize.TokenError -- not caught anywhere in numpy.
np.load('file.npz')['data']
-> NpzFile.__getitem__ (line 178 _npyio_impl.py)
-> format.read_array()
-> _read_array_header() (line 661 _format_impl.py)
-> _filter_header()
-> tokenize.generate_tokens() raises TokenError [UNCAUGHT]
pip install numpy
python3 poc_numpy_npz.py
Expected output:
[+] CONFIRMED TokenError raised: ('too many nested parentheses', (1, 894))
[+] CONFIRMED TokenError ESCAPED ValueError handler: ...
depth=99: ValueError (safe)
depth=100: TokenError (VULNERABLE)
| Property | Value |
|---|---|
| Malicious NPZ size | 1,328 bytes |
| Inner .npy size | 1,214 bytes |
| Nesting depth | 100 levels |
| File | Purpose |
|---|---|
poc_numpy_npz.py | Working PoC -- generates malicious NPZ and demonstrates TokenError escape |
report.md | Full huntr-formatted report |
poc-evidence.html | Self-contained HTML evidence page with terminal output |
README.md | This file |
See numpy-poc/ for the same bug triggered via .npy directly.