Hugging Face Transformers Flaw Writes Malicious Python Code to Disk Before User Consent

A newly disclosed vulnerability in the Hugging Face Transformers library could allow attacker-controlled Python files to be written to a victim’s system before the user approves the execution of remote code. This vulnerability is tracked as CVE-2026-80047 and affects Transformers versions 4.49.0 through 5.8.1. According to the CERT Coordination Center Vulnerability Note VU#456290, the flaw […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: