Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.17% | — | Pollen Robotics Reachy MiniAIHuggingface SpacesAI | 23/9/2026 | 23/9/2026 | The Reachy Mini daemon exposes an HTTP API for managing the robot. Its app installation endpoint, POST /apps/install in src/reachy_mini/daemon/app/routers/apps.py, has no authentication. The handler's only dependency is Depends(get_app_manager), which just hands back the manager object from application state, so… | |
| Aplazada | Alta (8.7) | 0.94% | — | AxolotlAIHuggingface TransformersAI | 5/9/2026 | 23/9/2026 | Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face model repository selected as… | |
| Pendiente de análisis | Alta (7.1) | 0.47% | — | Huggingface TokenizersAI | 4/9/2026 | 24/9/2026 | tokenizers (Hugging Face) is affected by an out-of-bounds buffer access in BpeBuilder::build (tokenizers/src/models/bpe/model.rs). When loading a tokenizer.json via Tokenizer::from_file/from_str, the builder sizes a scratch buffer to the longest vocabulary key, then writes each concatenated merge rule into it. A merge… | |
| Pendiente de análisis | Alta (7.8) | 0.10% | — | Huggingface TransformersAI | 1/9/2026 | 23/9/2026 | A vulnerability in Hugging Face Transformers (versions 4.57.0 to 5.16.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate(). The function fetches and caches a remote module file before performing the required trust_remote_code consent… | |
| Pendiente de análisis | Alta (7.8) | 0.45% | — | Huggingface Pytorch Image ModelsAI | 20/8/2026 | 31/8/2026 | Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required to exploit this vulnerability in that the… | |
| Pendiente de análisis | Media (6.8) | 0.29% | — | Huggingface TransformersAI | 17/8/2026 | 24/9/2026 | Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and… | |
| Pendiente de análisis | Media (6.9) | 0.19% | — | Huggingface AccelerateAI | 10/8/2026 | 16/9/2026 | Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can supply relative paths with ../ sequences or absolute paths to read arbitrary… | |
| Aplazada | Alta (8.8) | 0.50% | — | Pytorch TorchAIHuggingface PeftAI | 5/8/2026 | 26/8/2026 | Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py line ~101) call torch.load on config-specified cache/covariance files without weights_only=True, bypassing peft's own safe-loading wrapper used elsewhere in the codebase. | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Huggingface TransformersAIHuggingface IdeficsAIHuggingface FlorenceAIHuggingface GemmaAI+2 | 2/8/2026 | 3/9/2026 | A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template` dictionary are used directly as filenames… | |
| Analizada | Media (6.9) | 0.79% | — | Huggingface Datasets | 24/7/2026 | 17/8/2026 | Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file_name values with directory traversal sequences to read… | |
| Aplazada | Media (4.4) | 0.17% | — | Huggingface DatasetsAI | 23/7/2026 | 23/7/2026 | Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-planting symlinks at predictable output paths. Attackers can redirect archive extraction to arbitrary filesystem locations in shared-cache… | |
| Aplazada | Media (5.3) | 0.40% | — | Huggingface DiffusersAI | 23/7/2026 | 23/7/2026 | Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or absolute paths in weight_map entries to… | |
| Aplazada | Media (6.9) | 0.43% | — | Huggingface Text-generation-inferenceAI | 16/7/2026 | 16/7/2026 | text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network attackers to coerce the server into issuing arbitrary HTTP GET requests by supplying a crafted image_url value in chat… | |
| Analizada | Alta (7.5) | 0.37% | — | Huggingface Diffusers | 15/7/2026 | 12/8/2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change, allowing a Hub… | |
| Modificada | Crítica (9.6) | 0.94% | — | Huggingface Transformers | 3/6/2026 | 28/8/2026 | A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by… | |
| Aplazada | Crítica (9.3) | 1.3% | — | OpenmedAIHuggingface TransformersAI | 2/6/2026 | 28/8/2026 | OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied model_name parameter, allowing a value such as attacker/foo-privacy-filter-bar to route through a path that loads Hugging… | |
| Analizada | Alta (7.8) | 0.60% | — | Huggingface Transformers | 24/5/2026 | 23/7/2026 | A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attacker-controlled HuggingFace Hub… | |
| Analizada | Alta (8.8) | 0.70% | — | Huggingface Diffusers | 14/5/2026 | 17/6/2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hugging Face Hub repositories. The _resolve_custom_pipeline_and_cls function in pipeline_loading_utils.py performs string… | |
| Modificada | Alta (8.8) | 0.89% | — | Huggingface Diffusers | 14/5/2026 | 28/8/2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulnerability has three variants, all sharing… | |
| Aplazada | Crítica (9.8) | 0.60% | — | MambaAIHuggingface HUBAIPytorchAI | 12/5/2026 | 17/6/2026 | The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-trained models from HuggingFace Hub. The MambaLMHeadModel.from_pretrained() method uses torch.load() to load the pytorch_model.bin weight file without enabling the security-restrictive weights_only=True… | |
| Aplazada | Media (6.3) | 0.42% | — | Huggingface TransformersAILmsys SglangAI | 2/5/2026 | 17/6/2026 | A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file python/sglang/srt/utils/hf_transformers_utils.py of the component HuggingFace Transformer Handler. The manipulation of the argument trust_remote_code with the input False as part of Boolean results in… | |
| Analizada | Crítica (9.3) | 0.95% | — | Huggingface Lerobot | 23/4/2026 | 14/7/2026 | LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. An unauthenticated network-reachable attacker can achieve… | |
| Analizada | Alta (7.8) | 0.38% | — | Huggingface Transformers | 7/4/2026 | 17/6/2026 | A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versions of the library… | |
| Analizada | Baja (2.1) | 0.73% | — | Huggingface Smolagents | 27/3/2026 | 17/6/2026 | A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the file src/smolagents/local_python_executor.py of the component Incomplete Fix CVE-2025-9959. This manipulation causes code injection. It is possible to initiate the… | |
| Analizada | Baja (2.1) | 0.55% | — | Huggingface Smolagents | 18/2/2026 | 17/6/2026 | A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExecutor. Executing a manipulation can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public… |