ESPnet 在 202609 版本之前,在反序列化预训练模型检查点时使用了 并设置 ,这使得攻击者可以通过精心构造的恶意文件触发任意代码执行。攻击者能够创建特殊的检查点文件,使其在通过初始化或微调路径加载时,在反序列化过程中执行攻击者指定的代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet