exllamav2 / README.md
n4u's picture
Upload 2 files
d8ff505 verified
|
Raw
History Blame Contribute Delete
1.37 kB
---
license: apache-2.0
tags:
- security
- proof-of-concept
- denial-of-service
---
# Malformed safetensors DoS PoC — exllamav2 `STFile` loader
This repository contains a single deliberately malformed `model.safetensors` file
that triggers an **unhandled exception (Denial of Service)** in the
[`turboderp-org/exllamav2`](https://github.com/turboderp-org/exllamav2) safetensors
loader (`exllamav2/stloader.py`, class `STFile`), verified against commit
`7dc12af3a81f34ac3f27cd7602ed539b638933ca` (package `exllamav2` 0.3.2).
The file's 8-byte header length says the JSON header is 5 bytes, but those bytes are
not valid JSON. `STFile.read_dict()` calls `json.loads(...)` on the header with no
error handling, so opening the file raises an uncaught `json.JSONDecodeError`. The
header is parsed the instant a model shard is opened during loading, so any service
that loads this file as a model crashes before any tensor is read.
## Reproduce
```bash
pip install exllamav2
python -c "from exllamav2.stloader import STFile; STFile.open('model.safetensors')"
```
Expected result: the process aborts with an uncaught `json.decoder.JSONDecodeError`
propagating out of `stloader.py`. (The header-parsing path runs before any
CUDA/C-extension code, so this reproduces on a CPU-only install.)
Harmless file: it triggers an unhandled exception, not code execution.