File size: 294 Bytes
aed65cd
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
# Core ML Path Traversal PoC

Crafted `.mlpackage` with path traversal in Manifest.json `path` field.

## Usage
```bash
pip install coremltools torch
python poc_coreml_path_traversal.py
```

## Root Cause
`ModelPackage.cpp` line 308/466: `m_packageDataDirPath / path` without canonicalization.