Huggingface
Huggingface Smolagents: vulnerabilidades y CVE
Huggingface Smolagents tiene 6 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses4
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-4963 | Baja (2.1) | 0.73% | — | 27 mar 2026 | A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the file src/smolagents/local_python_executor.py of the component… |
| CVE-2026-2654 | Baja (2.1) | 0.55% | — | 18 feb 2026 | A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExecutor. Executing a manipulation can lead to server-side request… |
| CVE-2025-14931 | Crítica (10) | 1.1% | — | 23 dic 2025 | Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of… |
| CVE-2025-11844 | Media (5.4) | 0.28% | — | 22 oct 2025 | Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function located in src/smolagents/vision_web_browser.py. The function constructs an XPath query by directly… |
| CVE-2025-9959 | Alta (7.6) | 0.31% | — | 3 sept 2025 | Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox, enforced by smolagents. The attack requires a Prompt Injection in order to trick the agent to… |
| CVE-2025-5120 | Crítica (10) | 25% | — | 27 jul 2025 | A sandbox escape vulnerability was identified in huggingface/smolagents version 1.14.0, allowing attackers to bypass the restricted execution environment and achieve remote code execution (RCE). The vulnerability stems… |