« Back to list

CVE-2026-4372

Status: AnalyzedHigh (7.8)—

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attacker-controlled HuggingFace Hub repository ID. When a victim loads this model using the standard `AutoModelForCausalLM.from_pretrained()` API, the library downloads and executes arbitrary Python code from the attacker's repository with the victim's full OS privileges.

Read full descriptionShow less

This issue arises due to unfiltered deserialization of configuration attributes, insufficient sanitization of internal fields, and unsandboxed execution of downloaded kernels. The vulnerability bypasses the `trust_remote_code` security mechanism, is invisible to the victim, and exploits the standard documented usage pattern, making it particularly severe. Users are advised to upgrade to version 5.3.0 or later to mitigate this issue.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

AV:L UI:R indica ejecución en cliente (T1203); desserialización maliciosa de config.json ejecuta código Python arbitrario (T1059) con privilegios del usuario (T1068).

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-4372",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-4372",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-26T15:08:29.632933Z"
        }
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security@huntr.dev",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@huntr.dev",
      "affectedData": [
        {
          "vendor": "huggingface",
          "product": "huggingface/transformers",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "5.3.0",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-24T14:16:16.917",
  "references": [
    {
      "url": "https://github.com/huggingface/transformers/commit/a7f8e7ff37d87d1a1a0c8cf607971c607741452f",
      "tags": [
        "Patch"
      ],
      "source": "security@huntr.dev"
    },
    {
      "url": "https://huntr.com/bounties/1f693a6e-6836-4b8b-a0bd-ca036fba8884",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "security@huntr.dev"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@huntr.dev",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1066"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attacker-controlled HuggingFace Hub repository ID. When a victim loads this model using the standard `AutoModelForCausalLM.from_pretrained()` API, the library downloads and executes arbitrary Python code from the attacker's repository with the victim's full OS privileges. This issue arises due to unfiltered deserialization of configuration attributes, insufficient sanitization of internal fields, and unsandboxed execution of downloaded kernels. The vulnerability bypasses the `trust_remote_code` security mechanism, is invisible to the victim, and exploits the standard documented usage pattern, making it particularly severe. Users are advised to upgrade to version 5.3.0 or later to mitigate this issue."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad crítica de ejecución remota de código en todas las versiones de la biblioteca HuggingFace transformers anteriores a la versión 5.3.0. La vulnerabilidad permite a un atacante crear un archivo 'config.json' malicioso que contiene el campo '_attn_implementation_internal' configurado con un ID de repositorio de HuggingFace Hub controlado por el atacante. Cuando una víctima carga este modelo utilizando la API estándar 'AutoModelForCausalLM.from_pretrained()', la biblioteca descarga y ejecuta código Python arbitrario del repositorio del atacante con los privilegios completos del sistema operativo de la víctima. Este problema surge debido a la deserialización no filtrada de atributos de configuración, la sanitización insuficiente de campos internos y la ejecución sin sandboxing de kernels descargados. La vulnerabilidad elude el mecanismo de seguridad 'trust_remote_code', es invisible para la víctima y explota el patrón de uso estándar documentado, lo que la hace particularmente grave. Se aconseja a los usuarios actualizar a la versión 5.3.0 o posterior para mitigar este problema."
    }
  ],
  "lastModified": "2026-07-23T17:10:00.123",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:huggingface:transformers:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCF55C52-9279-4B31-A8E9-004C31DA635F",
              "versionEndExcluding": "5.3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@huntr.dev"
}