ryansecuritytest-fanpierlabs's picture
Upload folder using huggingface_hub
7a13bae verified

PoC: SurrealML Normaliser Panic (DoS)

SECURITY RESEARCH ONLY

This .surml file contains an unknown normaliser type (UNKNOWN_NORMALISER) that causes a panic in NormaliserType::new() due to an unhandled match arm.

Affected code: modules/core/src/storage/header/normalisers/wrapper.rs Trigger: SurMlFile::from_file("malicious.surml")

Submitted to huntr.com by Ryan @ Fan Pier Labs