logo

Hugging Face Transformers Security Flaw Allows Remote Code Execution

ID: 47126189-d9f5-5370-82dc-716cc5321e39

STIX ID: report--47126189-d9f5-5370-82dc-716cc5321e39

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Divya

...
...

A critical RCE in Hugging Face Transformers (CVE-2026-4372) allowed malicious model configuration to trigger automatic download and execution of attacker-controlled kernel packages via the _attn_implementation_internal field when loading models; affected versions 4.56.0 through 5.2.x were patched in 5.3.0 and users are advised to upgrade, sandbox model-loading, and avoid untrusted models.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.