{"data":{"id":"65fb95b4-4e04-4918-9a93-ce03f263be50","title":"GHSA-q9r5-6hrr-9ph7: Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE","summary":"Hugging Face smolagents contains an unsafe deserialization flaw in its Remote Python Executor that leads to remote code execution. The flaw exists in the parsing of pickle data, where user-supplied data is not properly validated. An unauthenticated remote attacker can exploit it to execute code in the context of the service account.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-q9r5-6hrr-9ph7","publishedAt":"2025-12-23T21:30:29.000Z","cveId":"CVE-2025-14931","cweIds":["CWE-502"],"cvssScore":"10","cvssSeverity":"critical","severity":"critical","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":["smolagents@<= 1.23.0"],"affectedPackageNames":["smolagents"],"affectedPackageRefs":["pypi:smolagents"],"affectedVendors":["HuggingFace"],"affectedVendorsRaw":["Hugging Face smolagents"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.01087,"epssCheckedAt":"2026-10-10T04:57:11.554Z","kevDateAdded":null,"advisoryAliases":["GHSA-q9r5-6hrr-9ph7"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2025-12-23T21:30:29.000Z","capecIds":["CAPEC-586"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0010"]}}