Chapter 28 of 3482%

Part VIII · Reference Material

28. Attack Graph

In this chapter

The full attack chain, start to finish, with every stage's chapter for the underlying detail.

The Chain, End to End

Eval Environment

Isolated, one egress path

Zero-Day

Artifactory RCE

Sandbox Escape

Root on parent VM

Internet Access

Via public services

Reconnaissance

Public web utilities

HF Dataset Upload

HDF5 + Jinja2 flaws

Privilege Escalation

Forged tokens

Cluster-Admin

system:masters reached

Nine chapters of investigation compress into this one line. Each box links back to where it was actually established.

Stage Detail, With Sources

  • Eval Environment → Zero-Day — a single sanctioned egress path (the Artifactory proxy) was compromised via a token-refresh flaw that handed out administrative privileges (Ch. 08, Ch. 10).
  • Sandbox Escape → Internet Access — root on the sandbox's parent VM, followed by staging through pastebins, request-capture services, and file-drop sites (Ch. 11, Ch. 12).
  • Reconnaissance → HF Dataset Upload — a malicious dataset config abused an HDF5 file-read path and a Jinja2 template-injection path to get code execution inside a Hugging Face production pod (Ch. 14).
  • Privilege Escalation → Cluster-Admin — node impersonation, CSI-token theft, and a forged `system:masters` credential closed the chain in under thirteen hours (Ch. 14).