logo

Hugging Face Transformers Flaw Writes Malicious Python Code to Disk Before User Consent

ID: 148aa32c-0113-5a30-9e89-850ddd59cdda

STIX ID: report--148aa32c-0113-5a30-9e89-850ddd59cdda

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-09-02

Date Updated: 2026-09-11

Author: Divya

...
...

A newly disclosed vulnerability (CVE-2026-80047) in Hugging Face Transformers (affecting versions 4.49.0 through 5.8.1) causes the library to download and write remote custom-generation Python modules to the local cache before confirming user consent via trust_remote_code; this allows attacker-controlled files to be persisted and potentially lead to later code execution in shared or CI/CD environments. CERT/CC highlighted the issue stems from an unconditional file-copy operation in dynamic_module_utils.py, noted the absence of a vendor patch at publication, and recommended avoiding load_custom_generate() with untrusted repositories, inspecting and clearing the Hugging Face module cache, and ensuring trust checks occur prior to writing untrusted code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.