CVE-2026-22584 is a vulnerability tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed January 13, 2026; most recent activity January 13, 2026.
Vulnerabilities have been identified in popular AI and ML Python libraries used in Hugging Face models, allowing remote attackers to embed malicious code in metadata. This code executes automatically when a file with…