Skip to content
CriticalVulnerability

GHSA-q9r5-6hrr-9ph7: Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE

Published
Record updated
View JSON
Affected
  • smolagents <= 1.23.0
Fixed in
No fixed version was stated when the source was last read.
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
1.1%

Summary

Hugging Face smolagents contains an unsafe deserialization flaw in its Remote Python Executor that leads to remote code execution. The flaw exists in the parsing of pickle data, where user-supplied data is not properly validated. An unauthenticated remote attacker can exploit it to execute code in the context of the service account.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.