Model and package supply chain
Risks in the models, weights, datasets and packages that AI systems are built from, including malicious uploads and unsafe file formats.
- All items
- 84
- Last 90 days
- 16
- Change
- -57%vs 37 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 1 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 0 |
| Dec 2025 | 2 |
| Jan 2026 | 1 |
| Feb 2026 | 8 |
| Mar 2026 | 13 |
| Apr 2026 | 5 |
| May 2026 | 18 |
| Jun 2026 | 10 |
| Jul 2026 | 8 |
| Aug 2026 | 5 |
| Sep 2026 | 6 |
| Oct 2026 | 1 |
84 items
CVE-2024-11394: Hugging Face Transformers Trax model deserialization remote code execution
Nov 22, 2024HighVulnerabilitySecurityCVE-2024-11394CVE-2024-11394 is a remote code execution flaw in Hugging Face Transformers' handling of Trax model files. The component fails to validate user-supplied data, leading to deserialization of untrusted data. An attacker can run code in the context of the current user if the target visits a malicious page or opens a malicious file.
NVD/CVE DatabaseCVE-2024-11393: Hugging Face Transformers MaskFormer deserialization flaw enables code execution
Nov 22, 2024HighVulnerabilitySecurityCVE-2024-11393CVE-2024-11393 is a remote code execution flaw in the MaskFormer model of Hugging Face Transformers. The flaw sits in the parsing of model files, where user-supplied data is not properly validated, leading to deserialization of untrusted data. A remote attacker can run arbitrary code in the context of the current user, but only if the target visits a malicious page or opens a malicious file.
NVD/CVE DatabaseCVE-2024-5998: langchain FAISS.deserialize_from_bytes unsafe pickle deserialization
Sep 17, 2024HighVulnerabilitySecurityCVE-2024-5998CVE-2024-5998 affects the FAISS.deserialize_from_bytes function in langchain-ai/langchain, which allows pickle deserialization of untrusted data. The issue affects the latest version of the product, and it can lead to the execution of arbitrary commands via the os.system function. The weakness is classified as CWE-502, Deserialization of Untrusted Data.
Fix: The source links a patch in the langchain-ai/langchain commit 604dfe2d99246b0c09f047c604f0c63eafba31e7, but it does not state a fixed version or a configuration change.
NVD/CVE DatabaseMachine Learning Attack Series: Backdooring Pickle Files
Aug 28, 2022MediumNewsSecurityResearchA researcher backdoored a Python pickle file from a two-year-old Husky AI Google Colab notebook using fickling's --inject command. When the file was loaded by StyleGAN2-ADA's generate command, the injected code executed without affecting the program's output. The author notes that Google Drive mapped into Colab projects could expose that data to an attacker who tricks a user into opening a malicious pickle file.
Fix: Fickling's --check-safety command checks pickle files for malicious opcodes and --trace shows the opcodes. The author advises only opening pickle files that you created or trust.
Embrace The Red
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.