Views
No views yet
onnx 1.22.0.Constant tensor whose data is marked as externalonnx.numpy_helper.to_array() will auto-load that external tensor even when no trusted base directory was providedonnx.reference.ReferenceEvaluator(model_bytes) reaches the same sink automatically and returns the local file bytes as model outputrepro.py: creates a temporary working directory, places a local secret file there, builds a malicious ONNX model, and demonstrates both public exploit pathsonnx 1.22.01PYTHONPATH=/mnt/data/huntr/.pydeps-onnx \
2/home/thun/.cache/codex-runtimes/codex-primary-runtime/dependencies/python/bin/python3 \
3repro.py