nvflare-convert-pytorch

Warn

Audited by Socket on Sep 14, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
evals/files/checkpoint-pt/train.py

This fragment is not obviously malware by itself (no explicit exfiltration/shelling/networking is present), but it implements a well-known high-impact unsafe pattern: torch.load(..., weights_only=False) on a user-supplied checkpoint path. If the checkpoint file is not fully trusted, this can enable arbitrary code execution during deserialization. Mitigate by restricting to trusted checkpoints, validating/allowlisting paths, and using safer loading options (e.g., weights-only loading where compatible) plus integrity verification (hash/signature).

Confidence: 72%Severity: 78%
SecurityMEDIUM
evals/files/injection-pt/config.yaml

This YAML configuration is not inherently malicious code, but it explicitly enables downstream components to upload model weights, local dataset statistics, and (optionally) local filesystem path information to external HTTPS endpoints after each training round. That combination (remote URLs + upload_weights/include_local_paths + stated posting intent) is a notable privacy/security exfiltration risk if consuming code does not enforce strict destination allowlisting, authentication, consent, and redaction. No direct malware behavior is observable in the fragment itself, so malware likelihood is lower, but security risk remains significant.

Confidence: 62%Severity: 72%
Audit Metadata
Analyzed At
Sep 14, 2026, 10:11 PM
Package URL
pkg:socket/skills-sh/nvidia%2Fnvflare%2Fnvflare-convert-pytorch%2F@ea64fe3a29b28270c3c4e8878ef00dd52b6c2b0d2c3ab5b79209efb938abdde1
Security Audit — socket — nvflare-convert-pytorch