Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check

CERT Coordination Center Version 1 original

Imported from official source

Overview A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. …

This version

Version
1 of 4
Recorded
September 15, 2026 20:57
Change
Initial
Content hash
76b8a45459b78ebd884e83922f88fab2
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.