Frequency
3
occurrences
First Seen
June 4, 2026
Last Seen
September 1, 2026
Related Threat Clusters
-
Critical RCE Vulnerability Discovered in LLaMA-Factory WebUI
A critical remote code execution vulnerability, CVE-2026-58116, has been identified in LLaMA-Factory versions up to 0.9.5. The flaw allows attackers to execute arbitrary Python code by supplying a malicious model path…
3 articles · Updated July 1, 2026 -
Critical RCE Vulnerability in Hugging Face Transformers Library Disclosed
A critical remote code execution (RCE) vulnerability has been identified in the Hugging Face Transformers library, tracked as CVE-2026-4372. This flaw allows attackers to execute arbitrary code during model loading by…
6 articles · Updated June 4, 2026 -
Hugging Face Transformers Vulnerability Allows Unauthorized Code Execution
A vulnerability in the Hugging Face Transformers library (versions 4.49.0 to 5.8.1) enables remote attacker-controlled Python files to be written to a user's local disk without consent. This issue, tracked as…
4 articles · Updated September 2, 2026
Recent Intelligence Reports
- VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check — Kb.Cert · September 1, 2026
- Cvefeed High Severity Advisories Jun 30, 2026 CVE-2026-58116 - LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path cvefeed.io Open source — cvefeed.io · July 1, 2026
- Hugging Face Transformers contains critical remote code execution vulnerability — Letsdatascience · June 4, 2026
Related Entities
Zero-day Exploit
CVE-2025-14930
CVE-2026-58116
CWE-20 - Improper Input Validation
Cwe-502 - Deserialization Of Untrusted Data
CWE-94 - Code Injection
T1059 - Command and Scripting Interpreter
T1195 - Supply Chain Compromise
T1203 - Exploitation for Client Execution
Hugging Face Hub
LLaMA-Factory
Deserialization Of Untrusted Data