HighVulnerability
GHSA-fgcw-684q-jj6r: huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
- Identifiers
- CVE-2026-5241GHSA-fgcw-684q-jj6r
- Published
- Record updated
- Affected
- transformers < 5.5.0
- Fixed in
- 5.5.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.9%
Summary
A flaw in the LightGlue model loading path of huggingface/transformers 5.2.0 lets an attacker-controlled model repository run arbitrary code during model initialization. The `trust_remote_code` value, meant to block remote code, is overridden by the `trust_remote_code` setting read from the untrusted `config.json` and passed into nested `AutoConfig.from_pretrained()` calls. Code runs even when the victim calls `AutoModel.from_pretrained()` with `trust_remote_code=False`. The source rates the risk as high for inference servers, notebooks, CI/CD pipelines and evaluation workers, citing possible credential theft, lateral movement and persistence.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Topics
Related items
- MediumCVE-2026-100653: vLLM unpinned Hugging Face artifact loads for FunAudioChat and Tarsier2Same vendor · NVD/CVE Database
- HighGHSA-3hmm-rh5q-gwwr: LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loadingSame vendor · Hugging Face Security Advisories
- MediumCVE-2026-80047: Hugging Face Transformers writes remote Python files to disk before trust checkSame vendor · NVD/CVE Database
- HighCVE-2026-58474: whichllm code injection in run and snippet commands via GGUF filenamesSame vendor · NVD/CVE Database
- HighCVE-2026-79784: Vocos class instantiation from configuration via from_pretrainedSame vendor · NVD/CVE Database