Deserialization Vulnerability in Hugging Face Transformers
CVE-2025-14924

7.8HIGH

Key Information:

Vendor
CVE Published:
23 December 2025

What is CVE-2025-14924?

A vulnerability in Hugging Face Transformers allows remote attackers to execute arbitrary code due to improper validation of user-supplied data during checkpoint parsing. This flaw requires user interaction, as the target must access a malicious page or file. An attacker can exploit this issue to execute code within the context of the affected application, posing serious security risks to users.

Affected Version(s)

Transformers 95faabf0a6cd845f4c5548697e288a79e424b096

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.