Huggingface

Transformers

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 17.08.2026 20:36:00
  • Zuletzt bearbeitet 18.08.2026 13:17:41

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute pat...

  • EPSS 0.3%
  • Veröffentlicht 02.08.2026 15:10:53
  • Zuletzt bearbeitet 03.08.2026 16:16:33

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where ke...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 03.06.2026 14:16:46
  • Zuletzt bearbeitet 19.08.2026 12:18:33

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` param...

Medienbericht Exploit
  • EPSS 0.48%
  • Veröffentlicht 24.05.2026 13:40:40
  • Zuletzt bearbeitet 23.07.2026 17:10:00

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_in...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 07.04.2026 05:22:00
  • Zuletzt bearbeitet 28.04.2026 16:39:31

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_...

  • EPSS 0.32%
  • Veröffentlicht 23.12.2025 21:15:48
  • Zuletzt bearbeitet 21.01.2026 21:01:36

Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is req...

  • EPSS 0.38%
  • Veröffentlicht 23.12.2025 21:15:48
  • Zuletzt bearbeitet 21.01.2026 16:38:41

Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers....

  • EPSS 0.33%
  • Veröffentlicht 23.12.2025 21:15:48
  • Zuletzt bearbeitet 21.01.2026 16:43:32

Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is requi...

  • EPSS 0.33%
  • Veröffentlicht 23.12.2025 21:15:47
  • Zuletzt bearbeitet 15.01.2026 16:49:35

Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is requir...

  • EPSS 0.33%
  • Veröffentlicht 23.12.2025 21:15:47
  • Zuletzt bearbeitet 15.01.2026 16:49:21

Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required...