logo

Malicious Hugging Face Models Could Trigger Remote Code Execution

ID: 3f99c92b-89b9-5b98-a3b3-74fa43384ac1

STIX ID: report--3f99c92b-89b9-5b98-a3b3-74fa43384ac1

Feed Name: TechRepublic Security

Threat Score
80/100

Date Published: 2026-06-05

Date Updated: 2026-07-20

Author: Ken Underhill

...
...

Researchers disclosed CVE-2026-4372, a critical RCE in Hugging Face Transformers that lets attackers execute arbitrary code via a poisoned model config.json (when the optional kernels package is installed), bypassing trust_remote_code=False; the flaw can be triggered by a standard from_pretrained() call and may expose cloud credentials, API tokens, SSH keys, and other sensitive assets, creating significant AI supply-chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.