Malicious Hugging Face Models Could Trigger Remote Code Execution
ID: 3f99c92b-89b9-5b98-a3b3-74fa43384ac1
STIX ID: report--3f99c92b-89b9-5b98-a3b3-74fa43384ac1
Feed Name: TechRepublic Security
Threat Score
Researchers disclosed CVE-2026-4372, a critical RCE in Hugging Face Transformers that lets attackers execute arbitrary code via a poisoned model config.json (when the optional kernels package is installed), bypassing trust_remote_code=False; the flaw can be triggered by a standard from_pretrained() call and may expose cloud credentials, API tokens, SSH keys, and other sensitive assets, creating significant AI supply-chain risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
