← nejvýznamnější zprávy · všechny zprávy

EPSS 0.00

Hugging Face Transformers library writes remote code to disk prior to consent check

Classification: Critical, Solution: Unavailable, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-80047, Summary: A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before evaluating the trust_remote_code consent prompt, violating the security contract enforced across other…

Číst originál na NCSC-FI →

1 zpráva z 1 zdroje · první 3. 9. 04:00 · poslední 3. 9. 04:00 CZ · EN/orig

Hugging Face FI

tg: zranitelnost tp: AI

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-80047 7.8 3.1 · CISA-ADP 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.

Jak se o tom psalo 1

  1. · NCSC-FI FI nadpis události

    Hugging Face Transformers library writes remote code to disk prior to consent check

    Classification: Critical, Solution: Unavailable, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-80047, Summary: A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before evaluating the trust_remote_code consent prompt, violating the security contract enforced across other…