Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-5241

Опубликовано: 03 июн. 2026
Источник: nvd
CVSS3: 8
CVSS3: 9.6
CVSS3: 7.7
EPSS Низкий

Описание

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the trust_remote_code parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when loading a LightGlue model using AutoModel.from_pretrained() with trust_remote_code=False, the LightGlueConfig reads the trust_remote_code value from the untrusted config.json file and propagates it into nested AutoConfig.from_pretrained() calls. This results in the execution of attacker-provided Python modules, even when the victim explicitly disables remote code execution. The vulnerability poses a high risk for environments such as API inference servers, research notebooks, CI/CD pipelines, and model evaluation workers, potentially leading to credential theft, lateral movement, or

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:huggingface:transformers:5.2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 43%
0.00547
Низкий

8 High

CVSS3

9.6 Critical

CVSS3

7.7 High

CVSS3

Дефекты

CWE-829
CWE-829

Связанные уязвимости

CVSS3: 7.7
redhat
2 месяца назад

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when loading a LightGlue model using `AutoModel.from_pretrained()` with `trust_remote_code=False`, the `LightGlueConfig` reads the `trust_remote_code` value from the untrusted `config.json` file and propagates it into nested `AutoConfig.from_pretrained()` calls. This results in the execution of attacker-provided Python modules, even when the victim explicitly disables remote code execution. The vulnerability poses a high risk for environments such as API inference servers, research notebooks, CI/CD pipelines, and model evaluation workers, potentially leading to credential theft, lateral movement, ...

CVSS3: 8
github
2 месяца назад

huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path

EPSS

Процентиль: 43%
0.00547
Низкий

8 High

CVSS3

9.6 Critical

CVSS3

7.7 High

CVSS3

Дефекты

CWE-829
CWE-829