Remote Code Execution in Hugging Face smolagents
CVE-2025-14931
10CRITICAL
What is CVE-2025-14931?
A deserialization of untrusted data vulnerability in Hugging Face smolagents allows remote attackers to execute arbitrary code without requiring authentication. This flaw arises from improper validation when processing pickle data, permitting the deserialization of malicious input. Attackers can exploit this issue to execute harmful code within the context of the service account, posing a serious security risk.
Affected Version(s)
smolagents 1.22.0
