Remote Code Execution Vulnerability in Hugging Face Transformers Product
CVE-2025-14920
7.8HIGH
What is CVE-2025-14920?
A remote code execution vulnerability exists in the Hugging Face Transformers product due to improper validation during the deserialization process of model files. This allows attackers to execute arbitrary code when a user interacts with a malicious page or file. To successfully exploit this flaw, a user must be deceived into taking a specific action that triggers the vulnerability, highlighting the need for heightened awareness and proactive security measures.
Affected Version(s)
Transformers 9c8bd3fc1befe54f3efb9f385561eef49f060a70
