T09 · Insecure Skill Coding Practices
- Location
dlt_predictor_upgraded.py:1030- Finding
Automatic Unsafe Deserialization of a Joblib Model During Predictor Initialization
- Content
View full analysis
Vulnerability Details
File Location:
dlt_predictor_upgraded.py:980-983anddlt_predictor_upgraded.py:1030-1038
Vulnerability Type: Unsafe deserialization of a local Joblib/Pickle artifact
Risk Level: HighVulnerable Code
python # 数据文件路径(倒序文件,自动修正) self.data_path = '/mnt/d/cp/DLT历史数据_适配模型版.xlsx' # 尝试从磁盘加载已保存的模型 self._load_models()python def _load_models(self): """从磁盘加载模型(若存在)""" import joblib model_dir = self._get_model_dir() stacker_path = model_dir / 'stacker_.pkl' # 若stacker未训练过,尝试加载 if hasattr(self, 'stacker_') and hasattr(self.stacker_, 'fitted_') and not self.stacker_.fitted_: if stacker_path.exists(): try: self.stacker_ = joblib.load(str(stacker_path))Technical Analysis
DLTPredictorUpgradedautomatically calls_load_models()during object initialization. Ifmodels/stacker_.pklexists, the file is passed directly tojoblib.load()without validating its provenance, integrity, ownership, permissions, or expected object structure.Joblib model files use Python pickle-compatible deserialization. Pickle is an executable serialization format: crafted objects can invoke attacker-selected callables through methods such as
__reduce__while the file is being loaded. Consequently, checking that the file exists does not make it safe.The vulnerable path is also reachable through the documented
DLTFusionCompleteentry point. Its constructor creates aDLTPredictorUpgradedinstance, which triggers model loading without a separate user confirmation or trust decision.Attack Path
- An attacker obtains the ability to place or replace files under the Skill installation directory. This could occur through a compromised Skill archive, an untrusted shared workspace, an insecure update process, or overly permissiv ...[truncated 1058 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not deserialize untrusted Joblib or Pickle files. Prefer non-executable model formats supported by the relevant framework.
- Make model loading explicit rather than invoking it automatically from the constructor.
- If Joblib must be retained, distribute a trusted manifest containing cryptographic hashes or signatures and verify the model before loading it.
- Reject symbolic links and ensure the resolved model path remains inside the expected model directory.
- Require the model and its parent directory to have trusted ownership and restrictive permissions.
- Run model loading in a sandboxed, low-privilege worker without access to credentials, sensitive files, or unrestricted networking.
- Validate the loaded object's expected type and metadata after integrity verification. Type validation alone is not sufficient because malicious code executes during deserialization.
- Fail closed when integrity verification is unavailable or unsuccessful.
