Executive brief
Hugging Face PyTorch Image Models is a machine learning library used for computer vision tasks. A vulnerability in checkpoint file parsing allows remote attackers to execute arbitrary code when a user opens a malicious checkpoint file, potentially compromising the integrity and confidentiality of systems running this library.
Technical details
The vulnerability is a deserialization of untrusted data flaw in the checkpoint parsing logic of PyTorch Image Models. The affected code fails to properly validate user-supplied data before deserializing checkpoint files, enabling arbitrary code execution in the process context. The attack requires user interaction—specifically, the target must visit a malicious page or open a malicious checkpoint file. This is a local attack vector (user must interact with the file on their system), and the exploit results in arbitrary code execution with the privileges of the current process. The vulnerability was fixed in version 1.0.26.
Affected products
- Hugging Face PyTorch Image Models before 1.0.26
Timeline
- 2026-02-05: disclosed: Vulnerability reported to vendor
- 2026-07-30: patched: Fixed in v1.0.26
- 2026-07-30: advisory: Coordinated public release of advisory ZDI-26-523