{"data":{"id":"4c4f8f63-f3eb-4da9-a46d-0fffc53ece11","title":"GHSA-fgcw-684q-jj6r: huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path","summary":"A flaw in the LightGlue model loading path of huggingface/transformers 5.2.0 lets an attacker-controlled model repository run arbitrary code during model initialization. The `trust_remote_code` value, meant to block remote code, is overridden by the `trust_remote_code` setting read from the untrusted `config.json` and passed into nested `AutoConfig.from_pretrained()` calls. Code runs even when the victim calls `AutoModel.from_pretrained()` with `trust_remote_code=False`. The source rates the risk as high for inference servers, notebooks, CI/CD pipelines and evaluation workers, citing possible credential theft, lateral movement and persistence.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-fgcw-684q-jj6r","publishedAt":"2026-06-03T15:30:43.000Z","cveId":"CVE-2026-5241","cweIds":["CWE-829"],"cvssScore":"8","cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":["transformers@< 5.5.0 (fixed: 5.5.0)"],"affectedPackageNames":["transformers"],"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["HuggingFace transformers","LightGlue","AutoModel.from_pretrained"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00936,"epssCheckedAt":"2026-10-10T04:57:24.897Z","kevDateAdded":null,"advisoryAliases":["GHSA-fgcw-684q-jj6r"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-06-03T15:30:43.000Z","capecIds":["CAPEC-437"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]}}