T08 · Insecure Dependencies
- Location
references/multimodal.md:59- Finding
Mutable Remote Model Artifacts Without Immutable Revision Pinning
- Content
View full analysis
Vulnerability Details
File Location:
references/multimodal.md, lines 59–64
Vulnerability Type: Unpinned third-party model and processor artifacts
Risk Level: Mediumpython MODEL_ID = "google/gemma-4-12B-it" processor = AutoProcessor.from_pretrained(MODEL_ID) model = AutoModelForMultimodalCausalLM.from_pretrained( MODEL_ID, torch_dtype=torch.bfloat16, device_map="auto" )Technical Analysis
The example loads a processor and model from a mutable Hugging Face repository without supplying an immutable
revisioncommit hash. Consequently, two executions of the same example can retrieve different repository contents.This conflicts with the artifact-pinning guidance in
SKILL.md, which instructs users to pin remote Hugging Face artifacts and disable remote code execution. Although the shown calls do not explicitly enabletrust_remote_code, mutable model, tokenizer, configuration, and serialization artifacts still create a supply-chain and reproducibility risk.The reviewed code does not establish that arbitrary code execution is immediately possible. The direct consequences supported by the code are the ingestion of changed model artifacts, altered inference behavior, resource exhaustion from unexpectedly changed artifacts, and loss of build reproducibility. More severe effects would depend on the file formats accepted by the installed Transformers version and its artifact-loading behavior.
Attack Path
- An attacker compromises the referenced model repository or obtains authority to change its default branch or revision.
- The attacker replaces or modifies model, processor, tokenizer, or configuration artifacts.
- A developer follows the documented example without specifying a commit revision.
from_pretrained()resolves and downloads the changed repository contents.- The application loads the unreviewed artifacts, potentially causing manipulated inference outpu ...[truncated 640 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin both
from_pretrained()calls to the same verified immutable commit:python MODEL_ID = "google/gemma-4-12B-it" MODEL_REVISION = "VERIFIED_FULL_COMMIT_HASH" processor = AutoProcessor.from_pretrained( MODEL_ID, revision=MODEL_REVISION, trust_remote_code=False, ) model = AutoModelForMultimodalCausalLM.from_pretrained( MODEL_ID, revision=MODEL_REVISION, trust_remote_code=False, torch_dtype=torch.bfloat16, device_map="auto", ) -
Verify that the selected commit belongs to the intended publisher and document how it was reviewed.
-
Prefer safe serialization formats such as Safetensors and reject legacy executable serialization formats where supported.
-
For sensitive deployments, download artifacts in a controlled build stage, verify cryptographic hashes, scan them, and load from a read-only local directory with offline mode enabled.
-
Add an automated documentation or static-analysis check that rejects remote
from_pretrained()calls lacking an immutable revision.
-
