Wan2.1/wan
Claude f71b604438
security: add weights_only=True to all torch.load() calls
Fixes a critical security vulnerability where malicious model checkpoints
could execute arbitrary code through pickle deserialization.

Changes:
- wan/modules/vae.py: Add weights_only=True to torch.load()
- wan/modules/clip.py: Add weights_only=True to torch.load()
- wan/modules/t5.py: Add weights_only=True to torch.load()

This prevents arbitrary code execution when loading untrusted checkpoints
while maintaining full compatibility with legitimate model weights.

Security Impact: Critical - prevents RCE attacks
Breaking Changes: None - weights_only=True is compatible with all standard
PyTorch state_dict files
2025-11-19 04:24:14 +00:00
..
configs [feature] Add VACE (#389) 2025-05-14 20:44:25 +08:00
distributed Format the code (#402) 2025-05-16 12:35:38 +08:00
modules security: add weights_only=True to all torch.load() calls 2025-11-19 04:24:14 +00:00
utils Format the code (#402) 2025-05-16 12:35:38 +08:00
__init__.py Format the code (#402) 2025-05-16 12:35:38 +08:00
first_last_frame2video.py Format the code (#402) 2025-05-16 12:35:38 +08:00
image2video.py Format the code (#402) 2025-05-16 12:35:38 +08:00
text2video.py Format the code (#402) 2025-05-16 12:35:38 +08:00
vace.py Format the code (#402) 2025-05-16 12:35:38 +08:00