Code Injection Vulnerability in Hugging Face Transformers
CVE-2025-14926

7.8HIGH

Key Information:

Vendor
CVE Published:
23 December 2025

What is CVE-2025-14926?

This vulnerability in the Hugging Face Transformers software arises from insufficient validation of user-provided input within the convert_config function. By exploiting this flaw, an attacker can inject arbitrary Python code by offering a malicious checkpoint for conversion. The execution of this unauthorized code occurs in the context of the user who performs the conversion, posing substantial risks to system security.

Affected Version(s)

Transformers 4.57.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.