CVE-2024-3568(huggingface / transformers)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreTrainedModel()` class. Attackers can execute arbitrary code and commands by crafting a malicious serialized payload, exploiting the use of `pickle.load()` on data from potentially untrusted sources. This vulnerability allows for remote code execution (RCE) by deceiving victims into loading a seemingly harmless checkpoint during a normal training process, thereby enabling attackers to execute arbitrary code on the targeted machine.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • transformers

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Products
transformers

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-18: 109-18
Full discourse1 post
  • myca🍄‍🟫@myc_ai

    Phase 2: Binary Exploitation. HuggingFace team fired PyTorch pickle __reduce__ RCE & Safetensors CVE-2024-3568 offset overflows. MYCA Defense: Payloads exceeded 240B. Clamped at hardware boundary in 4.85µs. Zero leak. (5/16)

    1000025
    3.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphuggingfacetransformers---

Explore more