Downloads · 30 days
0
wildbits/orbax-non-ocdbt-absolute-path-poc
orbax-non-ocdbt-absolute-path-poc is a machine learning model from wildbits. Use it for the machine learning task on the model card, and read the license before you ship it in a product. It is set up for orbax.
This repository contains a harmless proof of concept for an absolute path injection issue in Orbax non-OCDBT PyTree checkpoint restoration.
Downloads · 30 days
0
Access
Public
Updated Jun 8, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
.py6.8 KB · 57%
From the Hugging Face model README
This repository contains a harmless proof of concept for an absolute path injection issue in Orbax non-OCDBT PyTree checkpoint restoration.
A malicious checkpoint can inject an absolute filesystem path through its _METADATA file. During metadata-driven restoration, Orbax may load compatible Zarr data from outside the checkpoint directory.
The proof of concept uses only a controlled local directory under /tmp. It does not access sensitive files, execute commands, or use the network.
orbax-checkpoint==0.12.0
malicious_checkpoint/
_METADATA
_CHECKPOINT_METADATA
params.bias/
params.weight/
controlled_outside/
.zarray
0
reproduce.py
generate_artifacts.py
requirements.txt
The malicious checkpoint intentionally does not contain an internal step/ directory.
Create a Python virtual environment and install the dependencies:
python -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
Run:
python reproduce.py
Expected output:
internal step directory exists: False
tensorstore path: /tmp/orbax-controlled-outside/
external value: 424242
POC SUCCESS
External Zarr data outside the checkpoint directory was loaded.
This demonstrates a checkpoint directory boundary escape. A malicious non-OCDBT Orbax checkpoint can cause compatible local Zarr data outside the checkpoint directory to be loaded during restoration.
This proof of concept does not claim arbitrary file read or remote code execution.