Sandbox Escape Vulnerability in Hugging Face SmolAgents Product
CVE-2025-5120
What is CVE-2025-5120?
A vulnerability has been discovered in Hugging Face's SmolAgents, specifically in version 1.14.0. This flaw allows attackers to circumvent the sandboxed execution environment, leading to potential remote code execution. The vulnerability arises from the local_python_executor.py module, which fails to adequately restrict the execution of Python code, despite attempts at both static and dynamic inspection. By exploiting whitelisted modules and functions, attackers can run arbitrary code on the host system, threatening the integrity of the core security intended to isolate untrusted code. This vulnerability opens the door to unauthorized code execution, data leakage, and possible compromise at the integration level. The issue has been addressed in SmolAgents version 1.17.0.
Affected Version(s)
huggingface/smolagents < 1.17.0