Copybara import of the project:

--
6ab68a057443f038a3d844807f205b1c99cab944 by Kevin Zakka <kevinarmandzakka@gmail.com>:

Fix pickle code-execution vulnerability in sysid loaders

Serialize signal_mapping as JSON so the trajectory and time series loaders can use allow_pickle=False, preventing arbitrary code execution from untrusted .npz files.

COPYBARA_INTEGRATE_REVIEW=https://github.com/google-deepmind/mujoco/pull/3353 from kevinzakka:sysid-disable-pickle-load 6ab68a057443f038a3d844807f205b1c99cab944
PiperOrigin-RevId: 935400242
Change-Id: Iecd907174441fbcfd02c106b912a7ff375c9098c
This commit is contained in:
Kevin Zakka
2026-06-20 15:10:17 -07:00
committed by Copybara-Service
parent 2cacf17071
commit a8eaccd2b6
3 changed files with 51 additions and 19 deletions
+3
View File
@@ -66,6 +66,9 @@ General
Bug fixes
^^^^^^^^^
- Fixed a vulnerability in the System Identification toolbox where loading a trajectory or time series called
``np.load`` with ``allow_pickle=True``, allowing arbitrary code execution from a malicious ``.npz`` file. Signal
metadata is now serialized as JSON and loaded with ``allow_pickle=False``.
- Fixed a bug in the ``mjz`` :ref:`decoder <mjpDecoder>` where unnormalized paths would fail to be read.
- Fixed a bug where the mesh compiler would produce non-unit convex hull polygon normals.