7 results (0.004 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

19 Nov 2024 — Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of configuration files. The issue results from the lack of proper validation of user-supplied data, w... • https://github.com/Piyush-Bhor/CVE-2024-11392 • CWE-502: Deserialization of Untrusted Data •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

19 Nov 2024 — Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of model files. The issue results from the lack of proper validation of user-supplied data, which... • https://github.com/Piyush-Bhor/CVE-2024-11393 • CWE-502: Deserialization of Untrusted Data •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 1

19 Nov 2024 — Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of model files. The issue results from the lack of proper validation of user-supplied data, which can ... • https://github.com/Piyush-Bhor/CVE-2024-11394 • CWE-502: Deserialization of Untrusted Data •

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 2

30 May 2024 — A code injection vulnerability exists in the huggingface/text-generation-inference repository, specifically within the `autodocs.yml` workflow file. The vulnerability arises from the insecure handling of the `github.head_ref` user input, which is used to dynamically construct a command for installing a software package. An attacker can exploit this by forking the repository, creating a branch with a malicious payload as the name, and then opening a pull request to the base repository. Successful exploitatio... • https://github.com/zunak/CVE-2024-39249 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 9.6EPSS: 0%CPEs: 1EXPL: 1

20 Dec 2023 — Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36. Deserialización de datos que no son de confianza en el repositorio de GitHub huggingface/transformers anteriores a 4.36. • https://github.com/huggingface/transformers/commit/1d63b0ec361e7a38f1339385e8a5a855085532ce • CWE-502: Deserialization of Untrusted Data •

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 1

19 Dec 2023 — Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36. Deserialización de datos que no son de confianza en el repositorio de GitHub huggingface/transformers anteriores a 4.36. • https://github.com/huggingface/transformers/commit/1d63b0ec361e7a38f1339385e8a5a855085532ce • CWE-502: Deserialization of Untrusted Data •

CVSS: 4.7EPSS: 0%CPEs: 1EXPL: 1

18 May 2023 — Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0. • https://github.com/huggingface/transformers/commit/80ca92470938bbcc348e2d9cf4734c7c25cb1c43 • CWE-377: Insecure Temporary File •