Critical Flaw in Hugging Face Transformers Lets Malicious Code Write to Disk Pre‑Execution
A security flaw uncovered in the popular Hugging Face Transformers library could let hostile actors place arbitrary Python files on a victim's computer before any remote code is executed. The vulnerability, catalogued as CVE‑2026‑80047, was initially reported by the security group GBHackers and has triggered warnings across the machine‑learning community.
The issue stems from a function in the library that, when handling model downloads, can be coerced into writing attacker‑specified files to the local filesystem without requiring explicit user consent. Because the library is widely used for loading and fine‑tuning large language models, the exploit could be triggered simply by a malicious model repository or a crafted URL supplied to a downstream application.
Researchers demonstrated that an adversary could embed a malicious payload in a model’s configuration metadata. When a user runs the standard `from_pretrained` call, the library processes the metadata and, due to insufficient validation, writes the payload to a temporary directory. The file remains on disk even if the subsequent remote‑code‑execution step is blocked, giving the attacker a foothold for later privilege escalation or data exfiltration.
Hugging Face has responded by releasing a patch that tightens validation of metadata fields and adds explicit user prompts before any file is written outside the intended cache location. The fix is included in version 5.2.1 of the Transformers package and is being back‑ported to earlier supported releases. Users are advised to upgrade immediately and to audit any custom model loading pipelines for untrusted sources.
The discovery highlights the broader risk of supply‑chain attacks in the AI ecosystem, where open‑source components are rapidly integrated into production workloads. Security experts recommend adopting a zero‑trust approach: verify model sources, employ sandboxed environments for model execution, and monitor filesystem changes during inference. As the community evaluates the impact of CVE‑2026‑80047, the incident serves as a reminder that even well‑maintained libraries can harbor critical bugs that affect a wide range of developers and organizations.
Comments (0)
Be the first to comment.
Join the discussion