Transformers vulnerabilities
CVEs whose affected-version data names the Transformers package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
20 CVEsRSS
CVE-2026-80047High· 7.8Hugging Face Transformers library writes remote code to disk prior to consent check
A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and <= 5.8.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate(). The function fetches …
CVE-2026-9856High· 7.1A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal
A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMix…
CVE-2026-5241High· 8.0huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
CVE-2026-4372High· 7.8HuggingFace transformers vulnerable to remote code execution
HuggingFace transformers vulnerable to remote code execution
CVE-2026-1839Medium· 6.5HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
CVE-2025-6921Medium· 5.3Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
CVE-2025-6051Medium· 5.3Hugging Face Transformers library has Regular Expression Denial of Service
Hugging Face Transformers library has Regular Expression Denial of Service
CVE-2025-6638Medium· 5.3Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
CVE-2025-5197Medium· 5.3Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2025-3933Medium· 5.3Transformers is vulnerable to ReDoS attack through its DonutProcessor class
Transformers is vulnerable to ReDoS attack through its DonutProcessor class
CVE-2025-3263Medium· 5.3Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking
Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking
CVE-2025-3777Low· 3.5Transformers's Improper Input Validation vulnerability can be exploited through username injection
Transformers's Improper Input Validation vulnerability can be exploited through username injection
CVE-2025-3264Medium· 5.3Transformers vulnerable to ReDoS attack through its get_imports() function
Transformers vulnerable to ReDoS attack through its get_imports() function
CVE-2025-3262Medium· 5.3Transformers vulnerable to ReDoS attack through its SETTING_RE variable
Transformers vulnerable to ReDoS attack through its SETTING_RE variable
CVE-2025-1194Medium· 4.3Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2024-12720Medium· 5.3Transformers Regular Expression Denial of Service (ReDoS) vulnerability
Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2024-11393High· 8.80dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11392High· 7.50dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11394High· 8.80dayPoCDeserialization of Untrusted Data in Hugging Face Transformers
Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-3568Low· 3.4PoCTransformers Deserialization of Untrusted Data vulnerability
Transformers Deserialization of Untrusted Data vulnerability