File size: 294 Bytes
aed65cd | 1 2 3 4 5 6 7 8 9 10 11 12 13 | # Core ML Path Traversal PoC
Crafted `.mlpackage` with path traversal in Manifest.json `path` field.
## Usage
```bash
pip install coremltools torch
python poc_coreml_path_traversal.py
```
## Root Cause
`ModelPackage.cpp` line 308/466: `m_packageDataDirPath / path` without canonicalization.
|