Hugging Face Transformers Vulnerability Allows Unauthorized Code Execution
Article Content
A vulnerability in the Hugging Face Transformers library (versions 4.49.0 to 5.8.1) enables remote attacker-controlled Python files to be written to a user's local disk without consent. This issue, tracked as CVE-2026-80047, arises from the library's custom generation-loading process, which performs a remote module fetch and local cache write before evaluating user consent. As a result, malicious code can be stored in the user's cache, potentially leading to unintended execution during future model loads. The flaw affects users who load models from untrusted repositories and is particularly concerning in environments where cache paths are reused. Currently, no patch or advisory from the vendor is available, and users are advised to avoid untrusted models and inspect their cache regularly. The vulnerability was reported by Prasanna Dabi and documented by the CERT Coordination Center.
Key Points: • CVE-2026-80047 affects Hugging Face Transformers versions 4.49.0 to 5.8.1. • Malicious Python files can be written to disk without user consent. • No vendor patch is available; users should avoid untrusted model repositories.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.