Remote Code Execution Vulnerability in Hugging Face Transformers by AI company
CVE-2025-14930
7.8HIGH
What is CVE-2025-14930?
The vulnerability in Hugging Face Transformers arises from improper validation during the parsing of weights, leading to potential deserialization of untrusted data. Attackers can exploit this flaw if a user interacts with malicious pages or files, enabling arbitrary code execution within the affected environment. This risky behavior puts installations at significant risk, emphasizing the necessity for vigilant security measures and updates.
Affected Version(s)
Transformers 4.57.1
