Unsafe Deserialization on .npz dataset leads to Remote Code Execution
Summary
Micro-ESPectre analysis tools load CSI dataset files with np.load(..., allow_pickle=True). A malicious .npz file containing an object-typed array executes attacker-controlled pickle code when a maintainer or developer runs documented tools such as tools/6_optimize_filter_params.py, tools/1_analyze_raw_data.py, or tools/10_train_ml_model.py.
The primitive is local code execution as the user running the analysis command. The most realistic attacker is a malicious dataset contributor or PR author who adds or replaces a .npz file in micro-espectre/data/** and waits for a maintainer to run the documented tooling.
Technical Detail
The shared dataset loader enables pickle support for every .npz file it scans or receives:
# micro-espectre/tools/csi_utils.py:861-864 @ 995601b30953441531b4e90217bca990013a6036
for sample_file in label_dir.glob('*.npz'):
try:
data = np.load(sample_file, allow_pickle=True)
sample = {key: data[key] for key in data.files}# micro-espectre/tools/csi_utils.py:893-895 @ 995601b30953441531b4e90217bca990013a6036
data = np.load(filepath, allow_pickle=True)
if 'gain_locked' in data.files:
return bool(data['gain_locked'])# micro-espectre/tools/csi_utils.py:912-916 @ 995601b30953441531b4e90217bca990013a6036
data = np.load(filepath, allow_pickle=True)
if 'csi_data' in data.files:
csi_array = data['csi_data']tools/6_optimize_filter_params.py has its own direct loader with the same setting:
# micro-espectre/tools/6_optimize_filter_params.py:220-228 @ 995601b30953441531b4e90217bca990013a6036
data_dir = Path(__file__).parent.parent / 'data'
baseline_file = find_latest_file(data_dir / 'baseline', 'baseline', chip_filter)
...
baseline_meta = np.load(baseline_file, allow_pickle=True)
if 'chip' in baseline_meta:
chip_filter = str(baseline_meta['chip'].item() if hasattr(baseline_meta['chip'], 'item') else baseline_meta['chip'])NumPy object arrays in .npy/.npz are pickle-backed. With allow_pickle=True, accessing an object-typed field such as chip or csi_data unpickles attacker-controlled data and invokes __reduce__.
References
https://owasp.org/www-community/vulnerabilities/Insecure_Deserialization