Skip to content
HighVulnerability

GHSA-fgcw-684q-jj6r: huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path

Published
Record updated
View JSON
Affected
  • transformers < 5.5.0
Fixed in
5.5.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.9%

Summary

A flaw in the LightGlue model loading path of huggingface/transformers 5.2.0 lets an attacker-controlled model repository run arbitrary code during model initialization. The `trust_remote_code` value, meant to block remote code, is overridden by the `trust_remote_code` setting read from the untrusted `config.json` and passed into nested `AutoConfig.from_pretrained()` calls. Code runs even when the victim calls `AutoModel.from_pretrained()` with `trust_remote_code=False`. The source rates the risk as high for inference servers, notebooks, CI/CD pipelines and evaluation workers, citing possible credential theft, lateral movement and persistence.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.