Hugging Face Flaw Lets Malicious AI Models Plant Python Code on User Systems

A newly disclosed vulnerability in Hugging Face Transformers could allow malicious AI model repositories to place attacker-controlled Python files on a user’s system before the user approves remote code execution. Tracked as CVE-2026-80047, the issue affects Hugging Face Transformers versions 4.49.0 through 5.8.1. The flaw lies in the library’s custom generation-loading process. It can allow […]

This article has been indexed from Cyber Security News

Read the original article: