¶ openai-community/gpt2
Risk: MEDIUM (Pickle Present) | Framework: PyTorch | Legal: UNKNOWN | License: Unknown
Each Monday morning we scan the top 50 most-downloaded text-generation models on Hugging Face for malicious pickle code, restrictive licensing, and other supply-chain risks. Findings here are surfaced as advisories, not as accusations. Every finding links to the source so you can verify.
Wondering what the scanner behind these findings does and doesn't catch? We publish that too — our bypass scorecard tests AIsbom against 11 documented pickle-scanner evasions, misses included.
📡 RSS feed →Risk: MEDIUM (Pickle Present) | Framework: PyTorch | Legal: UNKNOWN | License: Unknown
Risk: MEDIUM (Pickle Present) | Framework: PyTorch | Legal: UNKNOWN | License: Unknown
Risk: MEDIUM (Pickle Present) | Framework: PyTorch | Legal: UNKNOWN | License: Unknown
Risk: MEDIUM (Pickle Present) | Framework: PyTorch | Legal: UNKNOWN | License: Unknown
AISBOM does not coordinate with model authors before publishing advisories. We rely entirely on what our scanner observes when fetching the model's metadata over HTTP. Findings represent the state of the model at the time of the most recent scan and may not reflect updates published after that time.
If you are the maintainer of a flagged model and believe the finding is incorrect, please open an issue at Lab700xOrg/aisbom or email advisories@aisbom.io. We will rescan and update the advisory promptly.
Findings are not legal advice. Severity ratings reflect AISBOM's heuristic assessment, not a formal CVE.