In this chapter
The full attack chain, start to finish, with every stage's chapter for the underlying detail.
The Chain, End to End
Eval Environment
Isolated, one egress path
Zero-Day
Artifactory RCE
Sandbox Escape
Root on parent VM
Internet Access
Via public services
Reconnaissance
Public web utilities
HF Dataset Upload
HDF5 + Jinja2 flaws
Privilege Escalation
Forged tokens
Cluster-Admin
system:masters reached
Nine chapters of investigation compress into this one line. Each box links back to where it was actually established.
Stage Detail, With Sources
- Eval Environment → Zero-Day — a single sanctioned egress path (the Artifactory proxy) was compromised via a token-refresh flaw that handed out administrative privileges (Ch. 08, Ch. 10).
- Sandbox Escape → Internet Access — root on the sandbox's parent VM, followed by staging through pastebins, request-capture services, and file-drop sites (Ch. 11, Ch. 12).
- Reconnaissance → HF Dataset Upload — a malicious dataset config abused an HDF5 file-read path and a Jinja2 template-injection path to get code execution inside a Hugging Face production pod (Ch. 14).
- Privilege Escalation → Cluster-Admin — node impersonation, CSI-token theft, and a forged `system:masters` credential closed the chain in under thirteen hours (Ch. 14).