nvflare-convert-pytorch
Audited by Socket on Sep 14, 2026
2 alerts found:
Securityx2This fragment is not obviously malware by itself (no explicit exfiltration/shelling/networking is present), but it implements a well-known high-impact unsafe pattern: torch.load(..., weights_only=False) on a user-supplied checkpoint path. If the checkpoint file is not fully trusted, this can enable arbitrary code execution during deserialization. Mitigate by restricting to trusted checkpoints, validating/allowlisting paths, and using safer loading options (e.g., weights-only loading where compatible) plus integrity verification (hash/signature).
This YAML configuration is not inherently malicious code, but it explicitly enables downstream components to upload model weights, local dataset statistics, and (optionally) local filesystem path information to external HTTPS endpoints after each training round. That combination (remote URLs + upload_weights/include_local_paths + stated posting intent) is a notable privacy/security exfiltration risk if consuming code does not enforce strict destination allowlisting, authentication, consent, and redaction. No direct malware behavior is observable in the fragment itself, so malware likelihood is lower, but security risk remains significant.