
Phase 2: Binary Exploitation. HuggingFace team fired PyTorch pickle __reduce__ RCE & Safetensors CVE-2024-3568 offset overflows. MYCA Defense: Payloads exceeded 240B. Clamped at hardware boundary in 4.85µs. Zero leak. (5/16)
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreTrainedModel()` class. Attackers can execute arbitrary code and commands by crafting a malicious serialized payload, exploiting the use of `pickle.load()` on data from potentially untrusted sources. This vulnerability allows for remote code execution (RCE) by deceiving victims into loading a seemingly harmless checkpoint during a normal training process, thereby enabling attackers to execute arbitrary code on the targeted machine.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

Phase 2: Binary Exploitation. HuggingFace team fired PyTorch pickle __reduce__ RCE & Safetensors CVE-2024-3568 offset overflows. MYCA Defense: Payloads exceeded 240B. Clamped at hardware boundary in 4.85µs. Zero leak. (5/16)
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | huggingface | transformers | - | - | - |