Downloads · 30 days
0
willardj/openvino-pathtrv-poc
openvino-pathtrv-poc is a machine learning model from willardj. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
Incomplete sanitizepath() fix in ONNX external data loading at tensorexternaldata.cpp:44-45.
Downloads · 30 days
0
Access
Public
Updated Mar 27, 2026
Repo size
918 B
Likes
0
Public
Click a slice to open those files.
Other1.5 KB · 42%
From the Hugging Face model README
Incomplete sanitize_path() fix in ONNX external data loading at tensor_external_data.cpp:44-45.
The implementation at file_util.cpp:107-113 only strips leading /.\\ characters:
const auto start = sanitized_path.find_first_not_of("/.\\");
return sanitized_path.substr(start);
Internal ../ sequences are not handled. A location like workspace/../../../etc/passwd starts with w (not stripped), preserving the full traversal path.
An ONNX model with external data tensor location set to workspace/../../../etc/passwd.
When loaded via openvino.Core().read_model(), the sanitized path is joined with the model directory, resolving to /etc/passwd.
import openvino as ov
# Load ONNX model with traversal in external data location
core = ov.Core()
model = core.read_model("poc_traversal.onnx")
# OpenVINO attempts to read /etc/passwd as tensor data
Arbitrary file read when loading crafted ONNX models from untrusted sources.
CWE-22 (Path Traversal)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N — 6.5