CriticalCERT/CCSep 01, 2026

VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check

Overview A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before evaluating the trust_remote_code consent prompt, violating the security contract enforced across other dynamic module-loading paths in the library. Description Hugging Face Transformers serves as a primary framework for defining and operating modern machine learning models including NLP, computer vision, audio, video, and multimodal systems, for both training and inference. As detailed in CVE‑2026‑80047 , affected vers

Why it matters

The weakness can enable direct compromise with limited attacker prerequisites, making internet-facing assets the first place to look.

What defenders should do

Identify affected versions, prioritize internet-facing systems, and apply the vendor remediation.

Verify at the source

CyberKit curates and prioritizes; the source remains authoritative. Read the original advisory at kb.cert.org →

Need to validate an indicator or network range?
Move from reading to action with the free CyberKit toolbox.
Use security tools