logoalt Hacker News

Blackthornyesterday at 2:12 PM1 replyview on HN

Edit: ignore this silliness, as it sidesteps the real problem. Leaving it here because we shouldn't remove our own stupidity.

It's pretty disappointing that safetensors has existed for multiple years now but people are still distributing pth files. Yes it requires more code to handle the loading and saving of models, but you'd think it would be worth it to avoid situations like this.


Replies

cpburns2009yesterday at 2:20 PM

safetensors is just as vulnerable to this sort of exploit using a pth file since it's a Python package.

show 1 reply