Downloads · 30 days
0
n4u/ollm
ollm is a machine learning model from n4u. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as apache-2.0.
Security proof-of-concept for a Denial-of-Service in Mega4alik/ollm (PyPI ollm, commit 6d1705a). Reported via huntr's Model File Vulnerability program.
Downloads · 30 days
0
Access
Public
Updated Jul 7, 2026
Repo size
91 B
Likes
0
Public
Click a slice to open those files.
Other1.5 KB · 59%
From the Hugging Face model README
Security proof-of-concept for a Denial-of-Service in
Mega4alik/ollm (PyPI ollm, commit 6d1705a).
Reported via huntr's Model File Vulnerability program.
oLLM ships its own hand-rolled safetensors parser (SafeTensorReader) with zero
header validation. model.safetensors is a 13-byte file whose header is not valid
JSON. Loading it through the parser crashes the process with an uncaught
json.JSONDecodeError, at model-load time, before any tensor data is read. This
affects any app using ollm to load a model (its core use case — it streams models
downloaded from the Hugging Face Hub).
pip install ollm — no GPU required, crash precedes any torch/CUDA op:
from ollm.gds_loader import SafeTensorReader
SafeTensorReader("model.safetensors")
# -> json.decoder.JSONDecodeError (uncaught -> loader crash)