Vulnerability Management Critical vulnerability in Hugging Face Transformers library allowed arbitrary code execution June 4, 2026 Share By SC Staff (Credit: Robert – stock.adobe.com) Coverage from Silicon Angle indicates a critical remote code execution vulnerability has been disclosed in Hugging Face Inc.’s Transformers library. This flaw allowed attacker-controlled artificial intelligence models to run arbitrary code on a victim’s machine, bypassing standard security measures. The vulnerability, tracked as CVE-2026-4372, was exploitable through a standard model-loading command, even when Hugging Face’s recommended security setting "trust_remote_code=False" was enabled. Attackers could embed a malicious payload within a model's configuration file, which would then execute silently upon loading the model using the "from_pretrained()" function. This bypasses previous security assumptions that disabling remote code execution protected users. Vulnerable versions of the Transformers library, specifically versions 4.56.0 through 5.2.x when the "kernels" package was installed, were downloaded an estimated 232 million times in the six months the flaw was active. Successful exploitation could lead to the theft of sensitive data such as cloud credentials, API keys, SSH keys, and proprietary datasets, with enterprise AI platforms and automated model evaluation pipelines being particularly exposed targets. Hugging Face has since released a patch in version 5.3.0, recommending immediate upgrades and urging organizations to treat model loading as a code execution surface. Source: Silicon Angle SC Staff Related Vulnerability Management 9.8 Mirasvit bug actively exploited on Magento servers Steve Zurier June 4, 2026 CISA warns of an actively exploited Magento extension flaw that enables remote code execution. Vulnerability Management WordPress Kirki plugin vulnerability allows account takeover SC Staff June 4, 2026 The vulnerability, present in Kirki versions 6.0.0 through 6.0.6, stems from an unauthenticated REST API endpoint that allows attackers to reset any user's password. Vulnerability Management Acer addresses critical zero-day vulnerabilities in Wave 7 routers SC Staff June 3, 2026 The first vulnerability, CVE-2026-49200, is a broken access control flaw that allows unauthenticated attackers to access plaintext credentials from log archives, potentially leading to unauthorized system access. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds