{"schema_version":1,"title":"Hugging Face Transformers vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in Hugging Face Transformers: 0 in the last 7 days and 4 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-80047, was published on 1 September 2026.","url":"https://junglewise.ai/threats/technologies/transformers","json_url":"https://junglewise.ai/threats/technologies/transformers.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/transformers","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":7,"all_time":11,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":1,"last_90_days":4,"last_365_days":6},"latest":[{"cve":"CVE-2026-80047","cvss":7.8,"epss":0.001,"slug":"cve-2026-80047-hugging-face-transformers-arbitrary-file-write-via-load-custom","title":"Hugging Face Transformers arbitrary file write via load_custom_generate","severity":"high","exploited":false,"published_at":"2026-09-01T14:17:41.943+00:00","url":"https://junglewise.ai/threats/cve-2026-80047-hugging-face-transformers-arbitrary-file-write-via-load-custom"},{"cve":"CVE-2026-9856","cvss":7.1,"epss":0.0046,"slug":"cve-2026-9856-hugging-face-transformers-path-traversal-in-save-pretrained","title":"A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. Th","severity":"high","exploited":false,"published_at":"2026-08-02T16:16:25.413+00:00","url":"https://junglewise.ai/threats/cve-2026-9856-hugging-face-transformers-path-traversal-in-save-pretrained"},{"cve":"CVE-2025-3933","cvss":3.1,"epss":0.0044,"slug":"cve-2025-3933-hugging-face-transformers-redos-in-donutprocessor","title":"PYSEC-2026-1977 - Transformers is vulnerable to ReDoS attack through its DonutProcessor class","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:57.564922+00:00","url":"https://junglewise.ai/threats/cve-2025-3933-hugging-face-transformers-redos-in-donutprocessor"},{"cve":"CVE-2024-3568","cvss":3,"epss":0.0208,"slug":"cve-2024-3568-hugging-face-transformers-deserialization-of-untrusted-data","title":"PYSEC-2026-1978 - Transformers Deserialization of Untrusted Data vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:37.939935+00:00","url":"https://junglewise.ai/threats/cve-2024-3568-hugging-face-transformers-deserialization-of-untrusted-data"},{"cve":"CVE-2026-5241","cvss":8,"epss":0.0094,"slug":"cve-2026-5241-hugging-face-transformers-rce-in-lightglue-model-loading","title":"Hugging Face Transformers RCE in LightGlue model loading","severity":"high","exploited":false,"published_at":"2026-06-03T14:16:46.337+00:00","url":"https://junglewise.ai/threats/cve-2026-5241-hugging-face-transformers-rce-in-lightglue-model-loading"},{"cve":"CVE-2026-4372","cvss":7.8,"epss":0.006,"slug":"cve-2026-4372-huggingface-transformers-remote-code-execution-via-config-json","title":"HuggingFace transformers remote code execution via config.json","severity":"high","exploited":false,"published_at":"2026-05-24T14:16:16.917+00:00","url":"https://junglewise.ai/threats/cve-2026-4372-huggingface-transformers-remote-code-execution-via-config-json"},{"cve":"CVE-2024-11393","cvss":8.8,"epss":0.0307,"slug":"cve-2024-11393-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in model parsing","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11393-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2024-11394","cvss":8.8,"epss":0.0257,"slug":"cve-2024-11394-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in model files","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11394-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2024-11392","cvss":7.5,"epss":0.0726,"slug":"cve-2024-11392-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in config handling","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11392-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2023-6730","cvss":3.1,"epss":0.0093,"slug":"cve-2023-6730-hugging-face-transformers-deserialization-of-untrusted-data","title":"PYSEC-2023-300 - Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.","severity":"low","exploited":false,"published_at":"2023-12-19T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-6730-hugging-face-transformers-deserialization-of-untrusted-data"},{"cve":"CVE-2023-2800","cvss":3.1,"epss":0.0029,"slug":"cve-2023-2800-hugging-face-transformers-insecure-temporary-file-in-model-loading","title":"PYSEC-2023-299 - Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0.","severity":"low","exploited":false,"published_at":"2023-05-18T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-2800-hugging-face-transformers-insecure-temporary-file-in-model-loading"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Hugging Face Diffusers","slug":"diffusers","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/diffusers"}],"technology":{"hub":true,"name":"Hugging Face Transformers","slug":"transformers","vendor":{"name":"Hugging Face","slug":"hugging-face","url":"https://junglewise.ai/threats/vendors/hugging-face"},"aliases":[],"category":"library","homepage":"https://huggingface.co/transformers/","description":"A Python library providing pre-trained transformer models for natural language processing and computer vision tasks.","url":"https://junglewise.ai/threats/technologies/transformers"},"most_severe":[{"cve":"CVE-2024-11393","cvss":8.8,"epss":0.0307,"slug":"cve-2024-11393-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in model parsing","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11393-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2024-11394","cvss":8.8,"epss":0.0257,"slug":"cve-2024-11394-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in model files","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11394-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2026-5241","cvss":8,"epss":0.0094,"slug":"cve-2026-5241-hugging-face-transformers-rce-in-lightglue-model-loading","title":"Hugging Face Transformers RCE in LightGlue model loading","severity":"high","exploited":false,"published_at":"2026-06-03T14:16:46.337+00:00","url":"https://junglewise.ai/threats/cve-2026-5241-hugging-face-transformers-rce-in-lightglue-model-loading"},{"cve":"CVE-2026-4372","cvss":7.8,"epss":0.006,"slug":"cve-2026-4372-huggingface-transformers-remote-code-execution-via-config-json","title":"HuggingFace transformers remote code execution via config.json","severity":"high","exploited":false,"published_at":"2026-05-24T14:16:16.917+00:00","url":"https://junglewise.ai/threats/cve-2026-4372-huggingface-transformers-remote-code-execution-via-config-json"},{"cve":"CVE-2026-80047","cvss":7.8,"epss":0.001,"slug":"cve-2026-80047-hugging-face-transformers-arbitrary-file-write-via-load-custom","title":"Hugging Face Transformers arbitrary file write via load_custom_generate","severity":"high","exploited":false,"published_at":"2026-09-01T14:17:41.943+00:00","url":"https://junglewise.ai/threats/cve-2026-80047-hugging-face-transformers-arbitrary-file-write-via-load-custom"},{"cve":"CVE-2024-11392","cvss":7.5,"epss":0.0726,"slug":"cve-2024-11392-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in config handling","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11392-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2026-9856","cvss":7.1,"epss":0.0046,"slug":"cve-2026-9856-hugging-face-transformers-path-traversal-in-save-pretrained","title":"A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. Th","severity":"high","exploited":false,"published_at":"2026-08-02T16:16:25.413+00:00","url":"https://junglewise.ai/threats/cve-2026-9856-hugging-face-transformers-path-traversal-in-save-pretrained"},{"cve":"CVE-2023-6730","cvss":3.1,"epss":0.0093,"slug":"cve-2023-6730-hugging-face-transformers-deserialization-of-untrusted-data","title":"PYSEC-2023-300 - Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.","severity":"low","exploited":false,"published_at":"2023-12-19T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-6730-hugging-face-transformers-deserialization-of-untrusted-data"},{"cve":"CVE-2025-3933","cvss":3.1,"epss":0.0044,"slug":"cve-2025-3933-hugging-face-transformers-redos-in-donutprocessor","title":"PYSEC-2026-1977 - Transformers is vulnerable to ReDoS attack through its DonutProcessor class","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:57.564922+00:00","url":"https://junglewise.ai/threats/cve-2025-3933-hugging-face-transformers-redos-in-donutprocessor"},{"cve":"CVE-2023-2800","cvss":3.1,"epss":0.0029,"slug":"cve-2023-2800-hugging-face-transformers-insecure-temporary-file-in-model-loading","title":"PYSEC-2023-299 - Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0.","severity":"low","exploited":false,"published_at":"2023-05-18T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-2800-hugging-face-transformers-insecure-temporary-file-in-model-loading"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}