© 2025-2026 PySpect
First version without a known vulnerability: 5.5.0
huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
Fixed in: 5.5.0
HuggingFace transformers vulnerable to remote code execution
Fixed in: 5.3.0
HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
Fixed in: 5.0.0rc3, 5.0.0
Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.
Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.
Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.
Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
Fixed in: 4.53.0
Hugging Face Transformers library has Regular Expression Denial of Service
Fixed in: 4.53.0
Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
Fixed in: 4.53.0
Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Fixed in: 4.53.0
Transformers is vulnerable to ReDoS attack through its DonutProcessor class
Fixed in: 4.52.1
Transformers vulnerable to ReDoS attack through its SETTING_RE variable
Fixed in: 4.51.0
Transformers vulnerable to ReDoS attack through its get_imports() function
Fixed in: 4.51.0
Transformers's Improper Input Validation vulnerability can be exploited through username injection
Fixed in: 4.52.1
Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking
Fixed in: 4.51.0
Hugging Face Transformers Regular Expression Denial of Service
Fixed in: 4.50.0, 8cb522b4190bd556ce51be04942720650b1a3e57, 4.49.0
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Fixed in: 4.50.0
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Fixed in: 4.48.0
Deserialization of Untrusted Data in Hugging Face Transformers
Fixed in: 4.48.0
Deserialization of Untrusted Data in Hugging Face Transformers
Fixed in: 4.48.0
Deserialization of Untrusted Data in Hugging Face Transformers
Fixed in: 4.48.0
Transformers Deserialization of Untrusted Data vulnerability
Fixed in: 4.38.0
transformers has a Deserialization of Untrusted Data vulnerability
Fixed in: 4.36.0, 1d63b0ec361e7a38f1339385e8a5a855085532ce
transformers has a Deserialization of Untrusted Data vulnerability
Fixed in: 4.36.0, 1d63b0ec361e7a38f1339385e8a5a855085532ce
transformers has Insecure Temporary File
Fixed in: 4.30.0, 80ca92470938bbcc348e2d9cf4734c7c25cb1c43