← Vulnerability feed

Vulnerability record · CVE-2026-5241 · published 3 June 2026

CVE-2026-5241: Huggingface transformers inclusion from untrusted sphere vulnerability

Huggingface · Transformers

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when loading a LightGlue model using `AutoModel.from_pretrained()` with `trust_remote_code=False`, the `LightGlueConfig` reads the `trust_remote_code` value from the untrusted `config.json` file and propagates it into nested `AutoConfig.from_pretrained()` calls. This results in the execution of attacker-provided Python modules, even when the victim explicitly disables remote code execution. The vulnerability poses a high risk for environments such as API inference servers, research notebooks, CI/CD pipelines, and model evaluation workers, potentially leading to credential theft, lateral movement, or persistence/backdoor deployment.

9.6 CVSS 3.1 Critical EPSS 0.94% · top 40.7% CWE-829 · Inclusion from untrusted sphere
9.6CVSS 3.1 base score
0.94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 2 tagged exploit
28 Aug 2026Last modified by NVD

Description

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when loading a LightGlue model using `AutoModel.from_pretrained()` with `trust_remote_code=False`, the `LightGlueConfig` reads the `trust_remote_code` value from the untrusted `config.json` file and propagates it into nested `AutoConfig.from_pretrained()` calls. This results in the execution of attacker-provided Python modules, even when the victim explicitly disables remote code execution. The vulnerability poses a high risk for environments such as API inference servers, research notebooks, CI/CD pipelines, and model evaluation workers, potentially leading to credential theft, lateral movement, or persistence/backdoor deployment.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-5241 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2024-3568Huggingface transformers deserialization of untrusted data vulnerabilityThe huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkp…EPSS 2.1%8.8CVE-2024-11393Huggingface transformers deserialization of untrusted data vulnerabilityHugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote at…EPSS 3.1%8.8CVE-2024-11394Huggingface transformers deserialization of untrusted data vulnerabilityHugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attacker…EPSS 2.6%8.8CVE-2024-11392Huggingface transformers deserialization of untrusted data vulnerabilityHugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attacke…EPSS 7.3%8.8CVE-2023-6730Huggingface transformers deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.EPSS 0.93%7.8CVE-2026-4372Huggingface transformers deserialization of untrusted data vulnerabilityA critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerabili…EPSS 0.60%7.8CVE-2026-1839Huggingface transformers deserialization of untrusted data vulnerabilityA vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_sta…EPSS 0.38%7.8CVE-2025-14928Huggingface transformers code injection vulnerabilityHugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exe…EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2026-5241), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.