CRITICAL🇵🇱 Wersja polska

CVE-2026-5241

CVSS 9.6v3.0pub. 2026-06-03upd. 2026-08-28

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when loading a LightGlue model using `AutoModel.from_pretrained()` with `trust_remote_code=False`, the `LightGlueConfig` reads the `trust_remote_code` value from the untrusted `config.json` file and propagates it into nested `AutoConfig.from_pretrained()` calls. This results in the execution of attacker-provided Python modules, even when the victim explicitly disables remote code execution. The vulnerability poses a high risk for environments such as API inference servers, research notebooks, CI/CD pipelines, and model evaluation workers, potentially leading to credential theft, lateral movement, or persistence/backdoor deployment.

🤖 AI Analysis
How it works

The problem is that the `LightGlueConfig` class reads the `trust_remote_code` parameter value from an untrusted `config.json` file controlled by the attacker, then passes this value to nested `AutoConfig.from_pretrained()` calls. As a result, despite calling `AutoModel.from_pretrained()` with the parameter `trust_remote_code=False`, this value is overwritten by data from the attacker's repository. This results in loading and executing Python modules supplied by the attacker during model initialization, completely bypassing the intended RCE protection mechanism.

Impact

An attacker controlling a malicious model repository can trigger arbitrary code execution on the victim's machine, which may result in credential theft, lateral movement in the network, or deployment of a backdoor ensuring persistent access.

Mitigation & patch

Apply patches available from the vendor according to references. A fix is available in the project repository at: https://github.com/huggingface/transformers/commit/676559d5022b74aaa0cee1cee0842b7f27c5320e. Until updating, avoid loading LightGlue models from untrusted repositories and verify the integrity of `config.json` files before model initialization.

Who is affected

Huggingface Transformers version 5.2.0, particularly environments using `AutoModel.from_pretrained()` to load LightGlue models — API servers, research notebooks, CI/CD pipelines, and model evaluation systems.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Huggingface Transformers

    APP
    Huggingface
    5.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-3568CRITICAL9.6PL ✓same product

RCE przez deserializację w bibliotece Huggingface Transformers

CVE-2026-4372HIGH7.8same product

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library ...

CVE-2026-1839HIGH7.8same product

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbit...

CVE-2025-14924HIGH7.8same product

Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability....

CVE-2025-14920HIGH7.8same product

Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerabilit...