CriticalVulnerability
GHSA-q9r5-6hrr-9ph7: Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE
- Identifiers
- CVE-2025-14931GHSA-q9r5-6hrr-9ph7
- Published
- Record updated
- Affected
- smolagents <= 1.23.0
- Fixed in
- No fixed version was stated when the source was last read.
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 1.1%
Summary
Hugging Face smolagents contains an unsafe deserialization flaw in its Remote Python Executor that leads to remote code execution. The flaw exists in the parsing of pickle data, where user-supplied data is not properly validated. An unauthenticated remote attacker can exploit it to execute code in the context of the service account.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- smolagentsPyPILLM dependency since 2024-12-27 · 7 tracked dependents
Related items
- MediumCVE-2026-100653: vLLM unpinned Hugging Face artifact loads for FunAudioChat and Tarsier2Same vendor · NVD/CVE Database
- HighGHSA-3hmm-rh5q-gwwr: LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loadingSame vendor · Hugging Face Security Advisories
- MediumCVE-2026-80047: Hugging Face Transformers writes remote Python files to disk before trust checkSame vendor · NVD/CVE Database
- HighCVE-2026-58474: whichllm code injection in run and snippet commands via GGUF filenamesSame vendor · NVD/CVE Database
- HighCVE-2026-79784: Vocos class instantiation from configuration via from_pretrainedSame vendor · NVD/CVE Database