YAML Metadata Warning:empty or missing yaml metadata in repo card
Check out the documentation for more information.
PoC: Path traversal in coremltools .mlpackage loader (CWE-22)
A crafted Core ML model package whose Manifest.json path field escapes the package
Data/ directory.
evil.mlpackage/Manifest.json— root itempathset to../../../../../../etc/hostname(a relative traversal escapingData/). InModelPackageImplthe value is joined to the packageData/dir viastd::filesystem::path::operator/with no containment check (ModelPackage.cpp:308validate,:466findItem,:516removeItem).operator/resolves..(and discards the base on an absolute path), so the resolved path leaves the package.
Reproduce (real compiled binding)
coreml_mlpackage_path_traversal_poc.py plants files outside a package and drives the
real coremltools.libmodelpackage.ModelPackage binding. On Linux, coremltools 9.0:
pip install coremltools
python coreml_mlpackage_path_traversal_poc.py
# [A read ] opened OK; validate() exists()'d the traversed path -> escaped to ../../OUTSIDE/secret.txt
# getRootModel path -> .../evil.mlpackage/Data/../../OUTSIDE/secret.txt (outside Data/)
# [A ctrl ] non-existent external target -> "Item does not exist for identifier: ROOT" (existence oracle)
(The Windows wheel omits the compiled libmodelpackage; run on Linux/macOS.)
Impact: out-of-package file resolution + host-path existence oracle on load; the same
unsanitized path reaches std::remove() in removeItem()/replaceRootModel()
(conditional file deletion when a consumer modifies the package).
Fix: reject path values that are absolute or contain .., and verify the joined path
stays within the package Data/ directory (weakly_canonical + lexically_relative).