AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

GHSA-wrfc-pvp9-mr9g: Deserialization of Untrusted Data in Hugging Face Transformers

OSV AI package advisories · observation · Nov 23, 2024 · UTC

Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of model files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerab

Read original source ↗ Open in workspace

recordType
vulnerability
status
active
evidenceStatus
reported
region
Global

Evidence & attribution

First collected: 2026-09-19T20:26:46.936Z. This is not the publication date.