Historical version

This is version 2, as it stood on . It is not what this organization currently publishes — read the current version.

VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check

CERT Coordination Center Version 2 imported change

Imported from official source

Overview A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. …

This version

Version
2 of 4
Recorded
September 18, 2026 09:42
Change
Imported change
Content hash
ecc1870993be6294bf9796d8d8b347b0
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.