High severity8.8NVD Advisory· Published Dec 19, 2023· Updated Jun 17, 2026
CVE-2023-6730
CVE-2023-6730
Description
Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
transformersPyPI | < 4.36.0 | 4.36.0 |
Affected products
3- huggingface/huggingface/transformersv5Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/huggingface/transformers/commit/1d63b0ec361e7a38f1339385e8a5a855085532cenvdPatchWEB
- huntr.com/bounties/423611ee-7a2a-442a-babb-3ed2f8385c16nvdExploitWEB
- github.com/advisories/GHSA-3863-2447-669pghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-6730ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/transformers/PYSEC-2023-300.yamlghsaWEB
News mentions
0No linked articles in our index yet.