Hugging Face Transformers library writes remote code to disk prior to consent check
Classification: Critical, Solution: Unavailable, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-80047, Summary: A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before evaluating the trust_remote_code consent prompt, violating the security contract enforced across other…
EPSS 0.00 CVE-2026-80047 Hugging Face FI