CVE-2024-3924: A code injection vulnerability exists in the huggingface/text-generation-inference repository, specifically within the `
Summary
A code injection vulnerability (injecting malicious code into a system) exists in the huggingface/text-generation-inference repository's workflow file, where user input from GitHub branch names is unsafely used to build commands. An attacker can exploit this by creating a malicious branch name and submitting a pull request, potentially executing arbitrary code on the GitHub Actions runner (the automated system that runs tests and builds for the project).
Solution / Mitigation
This issue was fixed in version 2.0.0. Users should update to version 2.0.0 or later.
Vulnerability Details
EPSS: 0.4%
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-3924
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%