CVE-2026-1839Disclosure(huggingface / transformers)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at line 3059 calls `torch.load()` without the `weights_only=True` parameter. This issue affects all versions of the library supporting `torch>=2.2` when used with PyTorch versions below 2.6, as the `safe_globals()` context manager provides no protection in these versions. An attacker can exploit this vulnerability by supplying a malicious checkpoint file, such as `rng_state.pth`, which can execute arbitrary code when loaded. The issue is resolved in version v5.0.0rc3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • transformers

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-07); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
transformers

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-19: 2Mentions · 2026-05-22: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-19: 204-0704-1905-22
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure2
2026-04-192
Disclosure2
2026-05-221
General1
Full discourse5 posts
  • cole murray@_colemurray
    Disclosure

    since we’re all in AI hacking panic mode, now would be a good time to disclose my AI security agent, waclaude, got arbitrary code execution in huggingFaces transformers library CVE-2026-1839 https://t.co/myYA5a2yDr

    Post summary

    The tweet announces the disclosure of CVE‑2026‑1839, a vulnerability that allows arbitrary code execution in the HuggingFace Transformers library.

    2212252.9K
    4.1K followersView on X
  • Mike Czumak@MikeCzumak
    General

    Well, after 5 years I’ve decided to start writing again, starting things off with a look at a recent CVE. A bit technical, but also highlights some gaps in the AI supply chain that might not be apparent. Nothing too crazy, I have my ease myself back in :) https://mikeczumak.com/cve-2026-1839-how-training-ai-with-heavy-weights-can-still-lead-to-light-security-bf4e34c9799c

    Post summary

    The post briefly references CVE‑2026‑1839 and links to a blog analysis, but provides no technical or actionable details about the vulnerability.

    00022163
    1.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1839 A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `sr… https://www.cve.org/CVERecord?id=CVE-2026-1839

    Post summary

    The post announces CVE-2026-1839, detailing a code‑execution vulnerability in HuggingFace Transformers’ Trainer class via the _load_rng_state method, with no PoC, exploit, or patch information supplied.

    01030562
    57.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-1839 A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `sr… https://www.cve.org/CVERecord?id=CVE-2026-1839 ----- Traducción: CVE-2026-1839 Una… http://infoflow.cloud`

    Post summary

    The post announces the CVE-2026-1839 vulnerability in HuggingFace Transformers' Trainer class, detailing that the `_load_rng_state()` method permits arbitrary code execution, but does not provide a PoC, exploit code, or patch information.

    0000042
    72 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1839 Arbitrary Code Execution in HuggingFace Transformers Trainer Class via Malicious Checkpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1839

    Post summary

    The entry discloses a new arbitrary code execution flaw in HuggingFace's Transformers Trainer class, triggered by a malicious checkpoint; no exploitation evidence, PoC, or patch information is provided.

    0000035
    4.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Apphuggingfacetransformers---
Apphuggingfacetransformers5.0.0--
Apphuggingfacetransformers5.0.0--
Apphuggingfacetransformers5.0.0--

Explore more