Model page

coqui/XTTS-v2 warn

downloads 8.5Mlikes 3.7klicense otherupdated 2023-12-11

chat template: not in config · view on Hugging Face ↗

Ingot findings

Static battery: 1 medium finding(s). Deep battery (behavioral differential, glitch-token pass) not yet run. Scanned 2026-08-20 (published from a community scan).

medium Pickle-serialized weights, no safetensors

Weights ship only as pickle-based files (dvae.pth, mel_stats.pth, model.pth, …). Loading pickle executes arbitrary code from the file — prefer a safetensors release or load in a sandbox.

How to fix

Convert the weights to safetensors before loading them anywhere that matters.

  1. Do not load the pickle files in-process — pickle deserialization executes arbitrary code from the file.
  2. Convert locally in a sandbox: `pip install safetensors` and use `safetensors.torch.save_file` on a state dict loaded with `torch.load(..., weights_only=True)` (refuses most code-execution payloads), or use Hugging Face's `convert.py` space/script.
  3. Pin the exact revision hash you converted from, and load only your converted safetensors artifact from then on.

Remediation guidance addresses the documented findings only. It is evidence-driven repair, not a safety certification of the model.

Verdict badge

Ship the verdict in your README — it always shows the latest published analysis:

Ingot verdict: warn

[![Ingot scan](https://ingot.tools/api/v1/models/coqui/XTTS-v2/badge.svg)](https://ingot.tools/models/coqui/XTTS-v2)
Gate it in CI