← Vulnerability feed

Vulnerability record · CVE-2026-1839 · published 7 April 2026

CVE-2026-1839: Huggingface transformers deserialization of untrusted data vulnerability

Huggingface · Transformers

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versions of the library supporting `torch>=2.2` when used with PyTorch versions below 2.6, as the `safe_globals()` context manager provides no protection in these versions. An attacker can exploit this vulnerability by supplying a malicious checkpoint file, such as `rng_state.pth`, which can execute arbitrary code when loaded. The issue is resolved in version v5.0.0rc3.

7.8 CVSS 3.1 High EPSS 0.38% · top 70.4% CWE-502 · Deserialization of untrusted data
7.8CVSS 3.1 base score
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versions of the library supporting `torch>=2.2` when used with PyTorch versions below 2.6, as the `safe_globals()` context manager provides no protection in these versions. An attacker can exploit this vulnerability by supplying a malicious checkpoint file, such as `rng_state.pth`, which can execute arbitrary code when loaded. The issue is resolved in version v5.0.0rc3.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-1839 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2026-5241Huggingface transformers inclusion from untrusted sphere vulnerabilityA vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execu…EPSS 0.94%9.6CVE-2024-3568Huggingface transformers deserialization of untrusted data vulnerabilityThe huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkp…EPSS 2.1%8.8CVE-2024-11393Huggingface transformers deserialization of untrusted data vulnerabilityHugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote at…EPSS 3.1%8.8CVE-2024-11394Huggingface transformers deserialization of untrusted data vulnerabilityHugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attacker…EPSS 2.6%8.8CVE-2024-11392Huggingface transformers deserialization of untrusted data vulnerabilityHugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attacke…EPSS 7.3%8.8CVE-2023-6730Huggingface transformers deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.EPSS 0.93%7.8CVE-2026-4372Huggingface transformers deserialization of untrusted data vulnerabilityA critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerabili…EPSS 0.60%7.8CVE-2025-14928Huggingface transformers code injection vulnerabilityHugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exe…EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2026-1839), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.