HighVulnerability
GHSA-29pf-2h5f-8g72: HuggingFace transformers vulnerable to remote code execution
- Identifiers
- CVE-2026-4372GHSA-29pf-2h5f-8g72
- Published
- Record updated
- Affected
- transformers < 5.3.0
- Fixed in
- 5.3.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.6%
Summary
All versions of the HuggingFace transformers library before 5.3.0 contain a critical remote code execution flaw. A malicious config.json whose _attn_implementation_internal field points to an attacker-controlled Hub repository ID causes the library, when loaded via AutoModelForCausalLM.from_pretrained(), to download and run arbitrary Python code with the victim's full OS privileges. The flaw bypasses the trust_remote_code safeguard and requires no action beyond the standard documented usage.
Mitigation
Fixed in 5.3.0. Users are advised to upgrade to version 5.3.0 or later.
Related items
- MediumCVE-2026-100653: vLLM unpinned Hugging Face artifact loads for FunAudioChat and Tarsier2Same vendor · NVD/CVE Database
- HighGHSA-3hmm-rh5q-gwwr: LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loadingSame vendor · Hugging Face Security Advisories
- MediumCVE-2026-80047: Hugging Face Transformers writes remote Python files to disk before trust checkSame vendor · NVD/CVE Database
- HighCVE-2026-58474: whichllm code injection in run and snippet commands via GGUF filenamesSame vendor · NVD/CVE Database
- HighCVE-2026-79784: Vocos class instantiation from configuration via from_pretrainedSame vendor · NVD/CVE Database