Model page
BAAI/bge-m3 warn
downloads 35.6Mlikes 3.4klicense mitarch xlm-robertaupdated 2024-07-03
chat template: not in config · view on Hugging Face ↗
Ingot findings
Static battery: 1 medium finding(s). Deep battery (behavioral differential, glitch-token pass) not yet run. Scanned 2026-08-20 (published from a community scan).
medium Pickle-serialized weights, no safetensors
Weights ship only as pickle-based files (colbert_linear.pt, pytorch_model.bin, sparse_linear.pt). Loading pickle executes arbitrary code from the file — prefer a safetensors release or load in a sandbox.
How to fix
Convert the weights to safetensors before loading them anywhere that matters.
- Do not load the pickle files in-process — pickle deserialization executes arbitrary code from the file.
- Convert locally in a sandbox: `pip install safetensors` and use `safetensors.torch.save_file` on a state dict loaded with `torch.load(..., weights_only=True)` (refuses most code-execution payloads), or use Hugging Face's `convert.py` space/script.
- Pin the exact revision hash you converted from, and load only your converted safetensors artifact from then on.
Remediation guidance addresses the documented findings only. It is evidence-driven repair, not a safety certification of the model.
Verdict badge
Ship the verdict in your README — it always shows the latest published analysis:
[](https://ingot.tools/models/BAAI/bge-m3)