Downloads · 30 days
0
willardj/openvino-exec-poc
openvino-exec-poc is a machine learning model from willardj. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
Code injection in the PyTorch frontend at src/bindings/python/src/openvino/frontend/pytorch/utils.py:204.
Downloads · 30 days
0
Access
Public
Updated Mar 27, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
.py2.1 KB · 44%
From the Hugging Face model README
Code injection in the PyTorch frontend at src/bindings/python/src/openvino/frontend/pytorch/utils.py:204.
Model forward() parameter names are interpolated into a Python class template and passed to exec() without sanitization.
poc_exec_injection.py creates a PyTorch model with a crafted forward() parameter name containing Python code. When openvino.convert_model() processes this model, the parameter name is interpolated into the template string and exec() runs the injected code.
pip install torch openvino
python poc_exec_injection.py
# Creates malicious_model.pt
python -c "
import torch, openvino as ov
model = torch.load('malicious_model.pt')
ov.convert_model(model)
# Injected code executes: id > /tmp/openvino-rce-proof.txt
"
cat /tmp/openvino-rce-proof.txt
# Shows: uid=... output from injected command
Arbitrary code execution when converting a malicious PyTorch model via openvino.convert_model(). Supply chain attack via models published to HuggingFace or shared internally.
CWE-94 (Improper Control of Generation of Code)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H — 8.1