CVE-2026-15679: Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This
Summary
Hugging Face PyTorch Image Models has a vulnerability where attackers can run arbitrary code on a system by tricking users into visiting a malicious page or opening a malicious file. The problem occurs because the software doesn't properly validate (check) checkpoint files before deserializing them (converting saved data back into usable objects), allowing attackers to inject malicious code that executes when the file is processed.
Vulnerability Details
EPSS: 0.0%
August 20, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-15679
First tracked: August 20, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 95%