PyTorch Users at Risk: Unveiling 3 Zero-Day PickleScan Vulnerabilities
jfrog.com | vulnerability | #ai-security | #supply-chain | #zero-day | #pickle | #pytorch | #picklescan
Summary
JFrog found three zero-days letting malicious models bypass PickleScan, the standard pickle scanner: scanning alone doesn't make PyTorch's pickle format safe—Safetensors migration still matters.
- Published
- Collected
Skip to content