CVE-2026-4372Disclosure(huggingface / transformers)

HIGHCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch huggingface transformers systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attacker-controlled HuggingFace Hub repository ID. When a victim loads this model using the standard `AutoModelForCausalLM.from_pretrained()` API, the library downloads and executes arbitrary Python code from the attacker's repository with the victim's full OS privileges. This issue arises due to unfiltered deserialization of configuration attributes, insufficient sanitization of internal fields, and unsandboxed execution of downloaded kernels. The vulnerability bypasses the `trust_remote_code` security mechanism, is invisible to the victim, and exploits the standard documented usage pattern, making it particularly severe. Users are advised to upgrade to version 5.3.0 or later to mitigate this issue.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1066CWE-502

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • transformers

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 22 mentions across 15 observed days

What's happening

  • Active exploitation reported across 5 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 19 signals
  • Disclosure: 8 classified signals
  • Peaked 8d ago at 4 mentions (2026-06-07); latest day: 2
  • 22 total mentions across 15 days

Affected systems

Products
transformers

Deep dive

Activity timeline22 mentions / 15d
01234Mentions · 2026-05-24: 1Mentions · 2026-05-25: 1Mentions · 2026-05-27: 1Mentions · 2026-06-04: 2Mentions · 2026-06-05: 1Mentions · 2026-06-06: 1Mentions · 2026-06-07: 4Mentions · 2026-06-08: 1Mentions · 2026-06-12: 1Mentions · 2026-06-18: 2Mentions · 2026-06-22: 1Mentions · 2026-06-27: 1Mentions · 2026-06-30: 1Mentions · 2026-07-02: 2Mentions · 2026-07-04: 2PoC Mentioned / Linked · 2026-06-04: 1PoC Mentioned / Linked · 2026-06-18: 1Active Exploitation · 2026-05-24: 1Active Exploitation · 2026-05-25: 1Active Exploitation · 2026-06-18: 2Active Exploitation · 2026-07-02: 1Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-06-04: 1Patch / Workaround · 2026-06-05: 1Patch / Workaround · 2026-06-07: 4Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-06-18: 2Patch / Workaround · 2026-07-02: 2Technical Details · 2026-05-24: 1Technical Details · 2026-05-27: 1Technical Details · 2026-06-04: 2Technical Details · 2026-06-06: 1Technical Details · 2026-06-07: 4Technical Details · 2026-06-08: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-18: 2Technical Details · 2026-06-27: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-02: 2Technical Details · 2026-07-04: 205-2405-2505-2706-0406-0506-0606-0706-0806-1206-1806-2206-2706-3007-0207-04
Signal classification4 categories
Disclosure
836.4%
Patch
627.3%
Active Exploitation
522.7%
General
313.6%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-05-241
Active Exploitation1
2026-05-251
Active Exploitation1
2026-05-271
General1
2026-06-042
Disclosure2
2026-06-051
Patch1
2026-06-061
Disclosure1
2026-06-074
Disclosure1Patch3
2026-06-081
Disclosure1
2026-06-121
Patch1
2026-06-182
Active Exploitation2
2026-06-221
General1
2026-06-271
Disclosure1
2026-06-301
General1
2026-07-022
Active Exploitation1Patch1
2026-07-042
Disclosure2
Full discourse20 posts
  • Pluto Security@pluto_security
    Disclosure

    The security assumption every AI team gets wrong: "As long as trust_remote_code=False is set, we are safe." ❌ We put that to the test. What we uncovered is a critical RCE vulnerability in @huggingface Transformers (CVE-2026-4372) that completely bypasses this control. A thread on how a routine model load turns into complete environment compromise 👇 1/3 🔍 The Exploit & ScaleBy abusing model configuration fields, an attacker can embed a malicious payload inside a configuration file. It executes arbitrary code even with remote code disabled. The affected versions were downloaded over 232M times while live. 2/3 🚨 The RiskSuccessful exploitation means full environment compromise—exposing cloud credentials, API keys, source code, and proprietary datasets. Impacts Transformers versions 4.56.0 through 5.2.x. 3/3 🛡️ Remediation• Upgrade to version 5.3.0 immediately. • Audit previously downloaded model configurations. • Move beyond checkbox security—static ecosystem flags aren't enough. Kudos to the Hugging Face team for the quick patch collaboration. 👇 Full technical breakdown link in the replies!

    Post summary

    The post announces a critical RCE vulnerability (CVE‑2026‑4372) in Hugging Face Transformers that bypasses trust_remote_code by embedding malicious code in configuration files, urges immediate upgrade to 5.3.0, and provides a technical breakdown link.

    2103801.7K
    2.5K followersView on X
  • Yotam Perkal@pyotam2
    Patch

    CVE-2026-4372 was just made public, though we identified and disclosed it to @huggingface back in February. While the HF team were quick to acknowledge and patch (they shipped a fix in just 10 days), it took almost three months from there until the CVE actually landed on NVD. During that gap, users had no real way of knowing they were susceptible to a trivial supply-chain attack that leads to arbitrary code execution just by running a model from HF, bypassing `trust_remote_code=False`. No special flags, no warnings, just a routine `from_pretrained()` call. Given the recent spike in supply chain attacks in the wild, this kind of vulnerability is especially concerning: vulnerable versions of Transformers were downloaded ~232M times, and even today over 23% of weekly installs are still pulling vulnerable versions. Techincal writeup: 🔗 https://pluto.security/blog/unauthenticated-remote-code-execution-in-huggingface-transformers-via-config-injection/

    Post summary

    CVE‑2026‑4372 is an arbitrary code execution flaw in Hugging Face Transformers that was patched by the vendor within ten days; the text highlights the vulnerability description and mitigation, but offers no proof of active exploitation or PoC.

    02030403
    624 followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 ثغرة حرجة في مكتبة Hugging Face Transformers تمكن من هجمات تنفيذ التعليمات البرمجية عن بعد تم الكشف عن ثغرة أمنية حرجة في مكتبة Hugging Face Transformers، تحمل رقم CVE-2026-4372، تسمح للمهاجمين بتنفيذ التعليمات البرمجية عن بعد (RCE) من خلال ملفات تكوين النماذج الضارة. تعرض هذه الثغرة خطرًا كبيرًا في سلسلة التوريد في أحد أكثر الأطر البرمجية للتعلم الآلي استخدامًا، وتؤثر على المطورين والمؤسسات وأنابيب الذكاء الاصطناعي عالميًا. يُنصح بتحديث المكتبة على الفور وتطبيق الإصلاحات الأمنية اللازمة. 🔗 للمزيد: https://cybersecuritynews.com/?p=151976

    Post summary

    A critical RCE vulnerability (CVE-2026-4372) in Hugging Face Transformers has been disclosed, urging immediate library updates and security patches.

    000401.7K
    314 followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    AI Security & Cybersecurity Intelligence Brief focused on verification-first strategies for multi-agent systems and SMBs. • It spotlights urgent threats including a critical Hugging Face Transformers RCE (CVE-2026-4372) via malicious configs, Meta AI support chatbot account takeovers, active Check Point VPN auth bypass, and a recent Mastra npm supply-chain backdoor stealing LLM keys and credentials. • Practical SMB takeaways stress immediate dependency upgrades, sandboxing untrusted AI models, credential rotation after incidents, and adopting cryptographic signing plus human oversight to counter agentic AI and supply-chain risks.

    Post summary

    The brief highlights an actively exploited Hugging Face Transformers RCE (CVE‑2026‑4372) and provides immediate mitigation recommendations for SMBs.

    10100112
    12.4K followersView on X
  • BnSnK@BunSnack
    Disclosure

    CVE-2026-4372: HuggingFace Transformers RCE via config injection. Bypasses trust_remote_code=False silently. 2.2B installs. No warnings. Just loading a model.

    Post summary

    The post announces a new remote code execution vulnerability (CVE-2026-4372) in HuggingFace Transformers, detailing how config injection can bypass restrictions and mentioning the high prevalence of impacted installations, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    000204
    6 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    CVSS 9.8: HuggingFace transformers' CVE-2026-4372 is under active exploitation, letting attackers execute arbitrary code via config injection. Patch now or assume full compromise. #NerdieNews #CyberSecurity #Vulnerability https://t.co/ABYxZxF3J3

    Post summary

    CVE‑2026‑4372 in HuggingFace transformers has a high CVSS score of 9.8, is actively exploited to allow arbitrary code execution via config injection, and a patch is urged immediately.

    00011141
    64 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    @huggingface We put that to the test. What we uncovered is a critical RCE vulnerability in @huggingface Transformers (CVE-2026-4372) that completely bypasses this control.

    Post summary

    Researchers have identified a critical RCE vulnerability (CVE‑2026‑4372) in Hugging Face Transformers that bypasses current controls, with no PoC, exploit, or patch information provided.

    1000049
    304 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-4372: The security assumption every AI team gets wrong: "As long as trustremotecode=False is set, we are safe." ❌ We put that to the test. What we uncovered is a critical RCE vulnerability in @huggingface Transformers (CVE-2026-4372) that completely bypasses this…

    Post summary

    The tweet announces the discovery of a critical RCE vulnerability (CVE-2026-4372) in HuggingFace Transformers that bypasses the trustremotecode=False security setting.

    1000072
    304 followersView on X
  • Ashok Kumar Singh@AIAshokSingh
    Patch

    Stop blindly loading community AI models into your notebooks. CVE-2026-4372 reveals a critical RCE vulnerability in Hugging Face Transformers. 🚨🔒 A malicious config.json can completely compromise your underlying machine terminal upon import. This is the third major HF supply chain RCE this month. Upgrade to ~5.3.0 and enforce mandatory cryptographic model provenance signing immediately. Lock down your research pods: http://www.mcal.in #HuggingFace #SupplyChainSecurity #DataScience

    Post summary

    CVE‑2026‑4372 exposes a critical RCE in Hugging Face Transformers via a malicious config.json; users are advised to upgrade to 5.3.0 and enforce cryptographic model signing as the immediate mitigation.

    0001055
    2.5K followersView on X
  • Slade 🛡️ AI Pentester@llm_redteam
    Active Exploitation

    ⚡️You loaded a model from Hugging Face. That alone was enough to run the attacker's code on your machine. CVE-2026-4372 hit Transformers, the most used AI library on the planet. A poisoned config.json could reach into private internal settings through a sloppy setattr() and execute code. Here is the nasty part. It walked straight past trust_remote_code=False, the exact switch people flip on to feel safe. No prompt. No exploit chain. You just open the model. [ WHERE ] Transformers v4.56.0 up to before v5.3.0 [ EXPOSURE ] about 6 months in the wild, Aug 2025 to Mar 2026 [ TRIGGER ] the optional kernels package installed [ FIX ] upgrade to Transformers 5.3.0+ Found by Yotam Perkal at Pluto Security. Every "safe" model you pulled in that window was a maybe. Update now and stop trusting config files.

    Post summary

    CVE‑2026‑4372 has been actively exploited in the wild for over six months through poisoned config files on Hugging Face Transformers; users should immediately upgrade to version 5.3.0 or newer.

    00010129
    1.1K followersView on X
  • Ignis@ahakcil
    General

    @Dani__oros @senb0n22a @One1S33175 @krea_ai Looks clean. No deserialization fuckery to sidestep safetensors and no CVE-2026-4372 even though its transformers==4.57.1 Haven't scrutinized every dependency in uv.lock but I probably won't. We are comfortably in the Hanlon's Razor area about the release.

    Post summary

    The tweet notes that the release appears free of the referenced CVE and deserialization issues, but offers no further technical details, patch information, or evidence of exploitation.

    00010107
    1.6K followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    Branch 1: Critical / Breaking Items (Immediate High-Impact Threats) 🔴 Why these matter most right now: Zero-days, active exploitation, and agentic failures with direct supply-chain and verification implications. 1.1 Hugging Face Transformers RCE (CVE-2026-4372) • Description: Critical remote code execution via malicious config.json in model loading (AutoModelForCausalLM.from_pretrained()). Attacker-controlled _attn_implementation_internal field bypasses trust_remote_code=False, triggering unsandboxed Python code execution from a malicious HF Hub repo. Affects versions before 5.3.0 (hundreds of millions of downloads). • Why it matters: Direct AI supply-chain compromise and “Trojan Horse” vector for agentic/multi-agent systems. Enables stealthy persistence, credential theft, or lateral movement in verification/provenance-weak environments. High SMB blast radius via common ML pipelines. • Recommended Actions: • Upgrade to 5.3.0+ immediately • Audit model sources/provenance • Avoid loading untrusted models without isolation/sandboxing • Scan for vulnerable kernels package • Verify with static analysis of configs • Source: Pluto Security / NVD / http://threat-modeling.com
Link: https://pluto.security/blog/unauthenticated-remote-code-execution-in-huggingface-transformers-via-config-injection/ 1.2 Meta AI Support Chatbot Account Takeovers (20k+ Instagram accounts) • Description: Hackers tricked the AI chatbot into resetting/changing emails and passwords on high-profile accounts (e.g., Obama-era White House page) via simple social engineering prompts, bypassing normal verification. Patched by Meta. • Why it matters: Demonstrates agentic AI as an exploitable intermediary for identity/authorization failures. Highlights measurability gaps in AI-human interfaces and correlated risks in multi-agent support systems. Relevant to “liability as a service” if agents act autonomously. • Recommended Actions: • For similar AI support tools: enforce human-in-loop for sensitive actions • Audit agent permissions • Monitor for anomalous prompt patterns • Users: Enable 2FA/MFA everywhere and review linked emails • Source: 404 Media / Krebs on Security / Ars Technica (early June 2026) 1.3 Check Point VPN Auth Bypass (CVE-2026-50751, CVSS 9.3, Active Exploitation) • Description: Logic flaw in deprecated IKEv1 certificate validation allows unauthenticated VPN access (no valid password needed). Actively exploited by Qilin ransomware affiliates. CISA KEV additions and urgent patching urged. • Why it matters: Classic supply-chain/infra risk for SMBs using VPNs. Enables initial access for broader compromises, including agentic systems behind perimeters. Flags correlated failures in legacy configs. • Recommended Actions: • Migrate from IKEv1 • Apply hotfixes immediately (or disable if unpatched) • Audit logs for unauthorized VPN sessions • Restrict management interfaces • CISA BOD 22-01 compliance • Source: Check Point / CISA / Rapid7 (June 8-16, 2026)

    Post summary

    The advisory highlights critical vulnerabilities in Hugging Face Transformers and Check Point VPN, confirms active exploitation of the latter by ransomware groups, provides a PoC link and patch recommendations, and urges immediate remediation.

    10000149
    12.4K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Hugging Face Transformers の脆弱性 CVE-2026-4372 が FIX:悪意のモデル読み込みと RCE https://iototsecnews.jp/2026/06/05/hugging-face-transformers-security-flaw-allows-remote-code-execution/ 機械学習モデルを利用する側からは、単なる設定データに見える “config.json” ですが、その処理方法に今回の問題の根本原因があります。ライブラリが内部の仕組みを動的に割り当てる際に、本来はユーザーが触れないはずの内部属性まで、そのまま受け入れてしまったことが、脆弱性 CVE-2026-4372 の引き金となりました。Hugging Face Transformers における脆弱性は、trust_remote_code を無効化している環境でもリモートコード実行が成立する極めて深刻なものです。すでに修正バージョンがリリースされていますので、該当する環境を運用しているチームは、速やかなアップグレードやサンドボックスの徹底などの対策を講じる必要があります。 #CVE20264372 #HuggingFace #Transformers #Vulnerability

    Post summary

    CVE-2026-4372 allows remote code execution in Hugging Face Transformers via config.json; a patch has been released, and users are urged to upgrade or sandbox.

    01000127
    499 followersView on X
  • Israel@f1tym1
    Disclosure

    Critical Hugging Face Transformers Vulnerability Enables Remote Code Execution Attacks https://ift.tt/GANj0zF A newly disclosed critical vulnerability in the HuggingFace Transformers library, tracked as CVE-2026-4372, allows attackers to achieve remote code execution (RCE) th…

    Post summary

    A new critical vulnerability (CVE-2026-4372) in HuggingFace Transformers allows remote code execution, but no PoC, exploit tool, patch, or evidence of active exploitation is mentioned.

    00010137
    991 followersView on X
  • DT@t_dharm
    Patch

    Tracked as CVE-2026-4372, the flaw was silently patched in Transformers 5.3.0 (released March 3) but affected every release since 4.56.0

    Post summary

    Transfomers released 5.3.0 silently fixed CVE-2026-4372, which had been affecting all releases from 4.56.0 onward.

    0001074
    15 followersView on X
  • AI Security Engineers@aiseceng
    General

    CVE-2026-4372: Transformers Config Field Turns Model Load into RCE. A model pull now equals third-party package risks! https://zpr.io/cyCYUqFdzVQd https://t.co/UGaT1qCA3E

    Post summary

    The post announces CVE‑2026‑4372, a Transformers‑library flaw that can lead to remote code execution when loading models, but offers no details on exploits, patches, or active attacks.

    00010114
    6.9K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-4372: Hugging Face Transformers Remote Code Execution Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04n3H_R0

    Post summary

    The article references CVE‑2026‑4372, a remote code execution flaw in Hugging Face Transformers, and promises guidance on business implications and response actions, but it provides no evidence of exploits, patches, or false‑positive claims.

    0000032
    31 followersView on X
  • IntegSec@integ_sec
    Disclosure

    Another month, another critical RCE in the AI model supply chain. CVE-2026-4372 turns a poisoned http://config.json into code execution in Hugging Face Transformers. That is the third one in 30 days. Out here in rural Maine we have a saying: you do not eat an apple you found on the side of the road. Same goes for models you did not build. If your stack loads third-party weights, your real attack surface is the loader, not the model. We are running free Recon pentests for AI companies right now. Find out what is actually exposed before someone else does: https://hubs.li/Q04mJd8_0

    Post summary

    The post discloses CVE‑2026‑4372, a critical RCE in the AI model supply chain that permits code execution via a poisoned config.json in Hugging Face Transformers, urging companies to conduct pentests to secure their third‑party models.

    0000060
    31 followersView on X
  • dc@lindecai
    Disclosure

    Hugging Face Transformers 曝出 RCE 漏洞 CVE-2026-4372,2.32 亿次下载受影响。 一个恶意 config.json 字段就能绕过 trust_remote_code=False 执行任意代码,加载模型 = 执行攻击者代码。 AI supply chain 安全不再是理论问题。生产环境加载第三方模型必须在沙箱中运行,且隔离所有 credentials。

    Post summary

    A new RCE vulnerability (CVE-2026-4372) in Hugging Face Transformers allows attackers to execute arbitrary code through a malicious config.json that bypasses trust_remote_code, affecting 2.32 billion downloads; no patch or exploit detail is provided.

    0000056
    67 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HuggingFace Transformers RCE — CVE-2026-4372 (7.8) Just loading a model runs attacker code: a malicious config.json executes via from_pretrained(), and trust_remote_code=False does NOT stop it. All versions <5.3.0 affected. Patch to 5.3.0. #AISecurity #infosec

    Post summary

    The tweet announces a remote code execution vulnerability (CVE-2026-4372) in HuggingFace Transformers and advises users to upgrade to version 5.3.0 for the fix.

    0000088
    207 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphuggingfacetransformers---

Explore more