YAML Metadata Warning:empty or missing yaml metadata in repo card
Check out the documentation for more information.
OpenVINO IR TensorIterator Port Map Validation Issue
A minimal reproduction of an input validation gap in OpenVINO's IR (Intermediate Representation) XML parser, specifically within TensorIterator and Loop layer deserialization.
Background
OpenVINO uses an XML-based format (.xml + .bin) to represent neural network models. The TensorIterator and Loop layers contain a port_map section that maps external ports to internal body subgraph ports via internal_layer_id attributes. These IDs are expected to reference Parameter (for inputs) or Result (for outputs) layers that exist within the <body> subgraph.
During deserialization (src/core/xml_util/src/xml_deserialize_util.cpp), the parser builds lookup maps (up_io_map.inputs / up_io_map.outputs) containing only the IDs of valid Parameter and Result layers found in the body. It then directly indexes these maps with internal_layer_id values read from XML attributes using std::map::at(), without first verifying that the key exists.
When a crafted model supplies an internal_layer_id that does not correspond to any Parameter or Result layer in the body, the parser throws an uncaught std::out_of_range exception, causing the loading process to abort.
Affected Code Paths
parse_input_description()โup_io_map.inputs.at(body_parameter_index)parse_output_description()โup_io_map.outputs.at(body_result_index)parse_purpose_attribute()โup_io_map.inputs.at(...)/up_io_map.outputs.at(...)
Files in this Repository
| File | Description |
|---|---|
poc_ti_invariant.xml |
Triggers the invariant input path (no axis attribute) |
poc_ti_sliced.xml |
Triggers the sliced input path (with axis attribute) |
poc_ti_output.xml |
Triggers the output description path |
poc_loop.xml |
Triggers the Loop purpose attribute path |
reproduce.py |
Automated reproduction script |
Reproduction
Prerequisites
pip install openvino
Run
python reproduce.py
Expected output for the invariant input path:
OpenVINO 2026.2.1-...
Devices: ['CPU']
[TEST] TensorIterator invariant input path
Loading poc_ti_invariant.xml...
Caught RuntimeError: Exception from src/inference/src/cpp/core.cpp:84:
Check 'false' failed at src/frontends/common/src/frontend.cpp:53:
Converting input model
unordered_map::at
=> Parser aborts on non-existent internal_layer_id
Root Cause
The internal_layer_id attribute in port_map entries is attacker-controlled XML data. The deserialization code assumes it always references a valid body layer, but never validates this assumption before the std::map::at() lookup.
Impact
Any application or service that loads untrusted OpenVINO IR models (e.g., model inference servers, CI/CD validation pipelines, model marketplaces) can be caused to abort by supplying a malformed .xml file.
No .bin weights file is required โ the crash occurs during pure XML topology parsing.
Tested Versions
openvino==2026.2.1-21919-ede283a88e3-releases/2026/2(PyPI)
Suggested Fix
Replace unchecked map.at(key) calls with map.find(key) + iterator validation:
auto it = up_io_map.inputs.find(body_parameter_index);
if (it == up_io_map.inputs.end()) {
OPENVINO_THROW("Invalid internal_layer_id: ", body_parameter_index,
" not found in body parameters");
}
const auto input_index = it->second;