File size: 1,368 Bytes
d8ff505 | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 | ---
license: apache-2.0
tags:
- security
- proof-of-concept
- denial-of-service
---
# Malformed safetensors DoS PoC — exllamav2 `STFile` loader
This repository contains a single deliberately malformed `model.safetensors` file
that triggers an **unhandled exception (Denial of Service)** in the
[`turboderp-org/exllamav2`](https://github.com/turboderp-org/exllamav2) safetensors
loader (`exllamav2/stloader.py`, class `STFile`), verified against commit
`7dc12af3a81f34ac3f27cd7602ed539b638933ca` (package `exllamav2` 0.3.2).
The file's 8-byte header length says the JSON header is 5 bytes, but those bytes are
not valid JSON. `STFile.read_dict()` calls `json.loads(...)` on the header with no
error handling, so opening the file raises an uncaught `json.JSONDecodeError`. The
header is parsed the instant a model shard is opened during loading, so any service
that loads this file as a model crashes before any tensor is read.
## Reproduce
```bash
pip install exllamav2
python -c "from exllamav2.stloader import STFile; STFile.open('model.safetensors')"
```
Expected result: the process aborts with an uncaught `json.decoder.JSONDecodeError`
propagating out of `stloader.py`. (The header-parsing path runs before any
CUDA/C-extension code, so this reproduces on a CPU-only install.)
Harmless file: it triggers an unhandled exception, not code execution.
|