Code Injection Vulnerability in Hugging Face Smolagents Affects Local Python Executor
CVE-2026-4963
Key Information:
- Vendor
Huggingface
- Status
- Vendor
- CVE Published:
- 27 March 2026
Badges
What is CVE-2026-4963?
A code injection vulnerability has been discovered in Hugging Face's smolagents version 1.25.0.dev0, specifically within the local Python executor. This issue arises from inadequate fixes related to a previous vulnerability, enabling potential remote code execution through manipulated function calls. The exploit has been publicly disclosed, raising concerns for users regarding the integrity and security of their systems, as it could be leveraged for various attack vectors. Despite early notification to the vendor, no response has been received.
Affected Version(s)
smolagents 1.25.0.dev0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
