YAML Metadata Warning:empty or missing yaml metadata in repo card

Check out the documentation for more information.

Security PoC β€” DeepLearning4J NormalizerSerializer unsafe reflection (huntr MFV)

Security-research PoC for a huntr MFV submission. Not malware β€” the demonstrator only writes harmless /tmp markers, and is a stand-in for a victim-classpath gadget (full RCE is gadget-gated).

malicious_model.zip carries a normalizer.bin with a CUSTOM header naming an attacker class. Loading it via the default ModelSerializer.restoreMultiLayerNetworkAndNormalizer(File,true) calls ND4JClassLoading.loadClassByName(name) = Class.forName(name, /*initialize=*/true) (static initializer runs) then Class.newInstance() (no-arg constructor runs) β€” both before the type is checked (CWE-470 unsafe reflection).

Environment

DL4J/ND4J 1.0.0-M2.1, JDK 17. Build the classpath from libs/ (via mvn dependency:copy-dependencies on the included pom.xml).

Reproduce

# compile the demonstrator + craft/load driver, then:
java -cp "out:libs/*" CraftAndLoad
#  [EvilNormalizerStrategy] WROTE marker /tmp/huntr_r2_normalizer_staticinit
#  [EvilNormalizerStrategy] WROTE marker /tmp/huntr_r2_normalizer_ctor
#  restore threw ClassCastException (expected, AFTER the sinks fire)

Both the static initializer and the no-arg constructor execute during the load. Files: src/CraftAndLoad.java (craft+load), src/EvilNormalizerStrategy.java (demonstrator), pom.xml (exact vulnerable deps).

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. πŸ™‹ Ask for provider support