Historical version

This is version 3, as it stood on . It is not what this organization currently publishes — read the current version.

VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check

CERT Coordination Center Version 3 imported change

Imported from official source

Overview A vulnerability in the Hugging Face Transformers library (versions 4.57.0 to 5.16.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. …

This version

Version
3 of 4
Recorded
September 23, 2026 18:00
Change
Imported change
Content hash
055c1d208fbd8ca1492d7b65236ae898
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.