Executive brief
Hugging Face Transformers is a popular machine learning library used to load and work with pre-trained AI models. The library contains a vulnerability in how it loads checkpoint files, which could allow an attacker to execute arbitrary code on a user's system by providing a malicious checkpoint file. An attacker could trick a developer or researcher into loading a crafted checkpoint file, potentially compromising their machine and sensitive model data.
Technical details
The vulnerability exists in the load_repo_checkpoint() function of the TFPreTrainedModel class, which uses pickle.load() to deserialize data from potentially untrusted checkpoint sources without proper validation. This is a classic deserialization vulnerability (CWE-502) where attackers can craft malicious pickle-serialized payloads to achieve arbitrary code execution. The attack vector is network-based with high complexity (requires user interaction to load the malicious checkpoint), and exploits an unprompted trust in checkpoint data during normal model loading workflows. An authenticated attacker or social engineering attack is required to deliver the payload. The vulnerability was patched in version 4.38.0 and affects all versions prior to this release.
Affected products
- Hugging Face Transformers before 4.38.0
Timeline
- 2024-04-10: disclosed
- 2024-04-10: patched: Fixed in version 4.38.0