TensorFlow.js weightsManifest.paths containment test

This repository is a benign local-only validation artifact for a Huntr model-format report.

The model file at model/model.json contains a TensorFlow.js weightsManifest entry whose paths value is ../outside_weight.bin. When tfjs-node loads model/model.json through the filesystem loader, the current implementation resolves that manifest entry with path.join(dirname(modelJsonPath), manifestPath) and reads the resulting file without checking that the canonical path remains inside the model directory.

This repo intentionally keeps the referenced file inside the repository root and outside only the model/ directory. It does not target live systems, does not read sensitive host files, and does not contain code for unauthorized access.

Expected secure behavior: reject weight shard paths that resolve outside the canonical model.json directory.

Observed vulnerable behavior in affected versions: the loader accepts the traversal segment and reads the external shard as model weight data.

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support