// posture advisories 100 provenance 75 resolution 100 xyz safety 100 load safety 100 supply chain 100 scanner trust 100 code execution 25 fig. 01 — posture on eight axes, 100 is clean. Weakest: code execution at 25. // the finding not scored no advisory applies to a version this model pins LOW
MEDIUM config.json declares `auto_map` — from_pretrained(trust_remote_code=True) executes Python shipped in this repo.
INFO authored against vulnerable: further detail on this finding is available to account holders.INFO inferred stack advisories: further detail on this finding is available to account holders.2 more findings on this model.
Author pfnet Task sentence-similarity Loader transformers License apache-2.0 Downloads 83,729 Remote code ships Python that runs on load (trust_remote_code) // dependencies 11 direct, 8 with findings, 50 reachable
Package Evidence Advisories Worst transformers direct, runtime 23 none pinned torch direct, runtime 13 none pinned numpy direct, install 8 hidden sentencepiece direct, install 1 hidden huggingface-hub direct, install 0 hidden safetensors direct, install 0 hidden tokenizers direct, install 0 hidden annotated-doc direct, install 0 hidden
Risk computed 2026-09-24 at 07:49 UTC. Dependencies come from the model's requirements, its declared loader and the code it ships; advisories from NVD, GHSA and OSV.
Model risk is computed from the model's declared and observed Python dependencies and the code it ships. If a finding is wrong, tell us. Report an issue with this page