Remote Code Execution Vulnerability in Hugging Face Transformers Product
CVE-2025-14928

7.8HIGH

Key Information:

Vendor
CVE Published:
23 December 2025

What is CVE-2025-14928?

A vulnerability in the Hugging Face Transformers library allows remote attackers to execute arbitrary code through the convert_config function. This flaw arises from inadequate validation of user-supplied strings, leading to potential remote code execution when a malicious checkpoint is processed. User interaction is necessary, making it crucial for users to avoid untrusted sources when converting checkpoints to prevent exploitation. This vulnerability emphasizes the need for stringent validation mechanisms in software libraries to safeguard against malicious attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Transformers 4.57.0

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.