Critical RCE Vulnerability in Hugging Face Transformers Library Disclosed

Critical RCE Vulnerability in Hugging Face Transformers Library Disclosed

First seen 4 Jun 2026, 16:54 UTC CsoonlineLetsdatascienceScworldGbhackersCybersecuritynews+1 85% similarity 72.0

Article Content

Browse articles
ThreatCluster

A critical remote code execution (RCE) vulnerability has been identified in the Hugging Face Transformers library, tracked as CVE-2026-4372. This flaw allows attackers to execute arbitrary code during model loading by bypassing the trust_remote_code=False safeguard. The vulnerability affects all versions from 4.56.0 to 5.2.x and was downloaded approximately 232 million times during its active period. Hugging Face released a patch for the vulnerability in version 5.3.0 on May 24, 2026. Security researchers from Pluto Security discovered the flaw, which can lead to the exposure of sensitive data such as cloud credentials and API keys. The exploit involves a parameter that appears innocuous but can execute malicious code without user consent. The vulnerability poses a significant risk to enterprise environments and automated AI pipelines.

Key Points: • CVE-2026-4372 allows RCE via Hugging Face Transformers library configurations. • The vulnerability affects versions from 4.56.0 to 5.2.x, with 232 million downloads during its active phase. • A patch was released on May 24, 2026, but many vulnerable versions remain in use.

ThreatCluster AI

Timeline

2025-12-23
CVE-2025-14930 published
CVE-2025-14930 was published, tracking a critical RCE vulnerability in Hugging Face Transformers.
Letsdatascience
2026-05-24
Patch for CVE-2026-4372 released
Hugging Face released a patch for the critical RCE vulnerability in version 5.3.0.
Csoonline
Recent
Vulnerability discovered by Pluto Security
Pluto Security reported a critical RCE vulnerability in Hugging Face Transformers, affecting millions of downloads.
Letsdatascience

Community

Browse all →