VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check

Imported from official source

Advisory

Cybersecurity Classified by Officially

A vulnerability in the Hugging Face Transformers library (versions 4.57.0 to 5.16.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before evaluating the trust_remote_code consent prompt, violating the security contract enforced across other dynamic module-loading paths in the library.

Hugging Face Transformers serves as a primary framework for defining and operating modern machine learning models including NLP, computer vision, audio, video, and multimodal systems, for both training and inference. As detailed in CVE‑2026‑80047, affected versions (4.57.0 to 5.16.1) implement GenerativePreTrainedModel.load_custom_generate() such that the library fetches and caches a remote Python module via get_cached_module_file() before evaluating user consent by resolve_trust_remote_code(). Although execution of the module is correctly gated, the initial file write is unconditional. As a result, remote code from a repository’s custom_generate/generate.py is copied into ~/.cache/huggingface/modules regardless of whether the user ultimately approves or declines the trust prompt. This behavior differs from other remote code-loading mechanisms in the Transformers library (including AutoConfig, AutoModel, AutoTokenizer, and AutoImageProcessor), all of which perform trust_remote_code verification before fetching or writing any remote Python content. The root cause is an unconditional file copy operation in dynamic_module_utils.py that occurs prior to consent evaluation and cannot be rolled back. An attacker may publish a model repository containing a malicious custom_generate/generate.py file. Any downstream user who loads the model reference triggers the file‑write behavior without requiring elevated privileges or additional interaction beyond the initial load attempt.

This is an extract. The publication continues at the source.

Read the original at the source: https://kb.cert.org/vuls/id/456290

Officially imported this from CERT Coordination Center’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

4 versions recorded. The original is kept in full — nothing is overwritten.

  1. v4 imported change on current
  2. v3 imported change on
  3. v2 imported change on
  4. v1 as first published on

Provenance

Organization
CERT Coordination Center — imported from official source
Official source
https://www.kb.cert.org/vuls/atomfeed/ ATOM
Imported
September 15, 2026 20:57
Versions
4 recorded
Identity
https://kb.cert.org/vuls/id/456290

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.