logoalt Hacker News

cpburns2009yesterday at 2:20 PM1 replyview on HN

safetensors is just as vulnerable to this sort of exploit using a pth file since it's a Python package.


Replies

Blackthornyesterday at 2:24 PM

Yeah, fair enough, the problem here is that the credentials were stolen, the fact that the exploit was packaged into a .pth is just an implementation detail.