VYPR

Transformers

by Huggingface

pypi: transformers

Source repositories

CVEs (33)

  • CVE-2026-68770CriJul 31, 2026
    risk 0.57cvss 9.8epss 0.01

    sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard condition includes an 'or…

  • CVE-2024-3568CriApr 10, 2024
    risk 0.56cvss 9.6epss 0.02

    The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreTrainedModel()` class. Attackers can execute arbitrary code and commands by crafting a malicious…

  • CVE-2026-5241CriJun 3, 2026
    risk 0.55cvss 9.6epss 0.01

    A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent…

  • CVE-2024-11392HigNov 22, 2024
    risk 0.54cvss 8.8epss 0.07

    Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this…

  • CVE-2025-14930HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this…

  • CVE-2025-14929HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required…

  • CVE-2025-14928HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this…

  • CVE-2025-14927HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this…

  • CVE-2025-14926HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this…

  • CVE-2025-14924HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit…

  • CVE-2025-14921HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to…

  • CVE-2025-14920HigDec 23, 2025
    risk 0.51cvss 7.8epss 0.00

    Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit…

  • CVE-2024-11394HigNov 22, 2024
    risk 0.50cvss 8.8epss 0.02

    Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this…

  • CVE-2024-11393HigNov 22, 2024
    risk 0.50cvss 8.8epss 0.03

    Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit…

  • CVE-2023-6730HigDec 19, 2023
    risk 0.50cvss 8.8epss 0.01

    Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.

  • CVE-2026-4372HigMay 24, 2026
    risk 0.44cvss 7.8epss 0.00

    A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an…

  • CVE-2026-1839HigApr 7, 2026
    risk 0.44cvss 7.8epss 0.00

    A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This…

  • CVE-2023-7018HigDec 20, 2023
    risk 0.44cvss 7.8epss 0.01

    Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.

  • CVE-2025-6921HigSep 23, 2025
    risk 0.42cvss 7.5epss 0.00

    The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer. The vulnerability arises from the _do_use_weight_decay method, which processes user-controlled regular expressions in…

  • CVE-2025-6638HigSep 12, 2025
    risk 0.42cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is present in version 4.52.4 and has been fixed in version…

Page 1 of 2