VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check

CERT Coordination Center Version 4 imported change current

Imported from official source

A vulnerability in the Hugging Face Transformers library (versions 4.57.0 to 5.16.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. …

This version

Version
4 of 4
Recorded
September 24, 2026 20:00
Change
Imported change
Content hash
75d1260571e92bf2393e0f3479bfded2
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.