← Vulnerability feed

Vulnerability record · CVE-2026-4372 · published 24 May 2026

CVE-2026-4372: Huggingface transformers deserialization of untrusted data vulnerability

Huggingface · Transformers

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attacker-controlled HuggingFace Hub repository ID. When a victim loads this model using the standard `AutoModelForCausalLM.from_pretrained()` API, the library downloads and executes arbitrary Python code from the attacker's repository with the victim's full OS privileges. This issue arises due to unfiltered deserialization of configuration attributes, insufficient sanitization of internal fields, and unsandboxed execution of downloaded kernels. The vulnerability bypasses the `trust_remote_code` security mechanism, is invisible to the victim, and exploits the standard documented usage pattern, making it particularly severe. Users are advised to upgrade to version 5.3.0 or later to mitigate this issue.

7.8 CVSS 3.0 High EPSS 0.60% · top 53.5% CWE-1066 · CWE-1066CWE-502 · Deserialization of untrusted data
7.8CVSS 3.0 base score
0.60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
23 Jul 2026Last modified by NVD

Description

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attacker-controlled HuggingFace Hub repository ID. When a victim loads this model using the standard `AutoModelForCausalLM.from_pretrained()` API, the library downloads and executes arbitrary Python code from the attacker's repository with the victim's full OS privileges. This issue arises due to unfiltered deserialization of configuration attributes, insufficient sanitization of internal fields, and unsandboxed execution of downloaded kernels. The vulnerability bypasses the `trust_remote_code` security mechanism, is invisible to the victim, and exploits the standard documented usage pattern, making it particularly severe. Users are advised to upgrade to version 5.3.0 or later to mitigate this issue.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-4372 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2026-5241Huggingface transformers inclusion from untrusted sphere vulnerabilityA vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execu…EPSS 0.94%9.6CVE-2024-3568Huggingface transformers deserialization of untrusted data vulnerabilityThe huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkp…EPSS 2.1%8.8CVE-2024-11393Huggingface transformers deserialization of untrusted data vulnerabilityHugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote at…EPSS 3.1%8.8CVE-2024-11394Huggingface transformers deserialization of untrusted data vulnerabilityHugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attacker…EPSS 2.6%8.8CVE-2024-11392Huggingface transformers deserialization of untrusted data vulnerabilityHugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attacke…EPSS 7.3%8.8CVE-2023-6730Huggingface transformers deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.EPSS 0.93%7.8CVE-2026-1839Huggingface transformers deserialization of untrusted data vulnerabilityA vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_sta…EPSS 0.38%7.8CVE-2025-14928Huggingface transformers code injection vulnerabilityHugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exe…EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2026-4372), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.