{"schema_version":1,"title":"Hugging Face vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 21 vulnerabilities in Hugging Face: 0 in the last 7 days and 12 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-85670, was published on 4 September 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/hugging-face","json_url":"https://junglewise.ai/threats/vendors/hugging-face.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/hugging-face","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":12,"all_time":21,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":2,"last_90_days":12,"last_365_days":16},"latest":[{"cve":"CVE-2026-85670","cvss":6.5,"epss":0.0047,"slug":"cve-2026-85670-hugging-face-tokenizers-buffer-overflow-in-bpebuilder","title":"Hugging Face tokenizers buffer overflow in BpeBuilder","severity":"medium","exploited":false,"published_at":"2026-09-04T15:17:44.993+00:00","url":"https://junglewise.ai/threats/cve-2026-85670-hugging-face-tokenizers-buffer-overflow-in-bpebuilder"},{"cve":"CVE-2026-80047","cvss":7.8,"epss":0.001,"slug":"cve-2026-80047-hugging-face-transformers-arbitrary-file-write-via-load-custom","title":"Hugging Face Transformers arbitrary file write via load_custom_generate","severity":"high","exploited":false,"published_at":"2026-09-01T14:17:41.943+00:00","url":"https://junglewise.ai/threats/cve-2026-80047-hugging-face-transformers-arbitrary-file-write-via-load-custom"},{"cve":"CVE-2026-15679","cvss":7.8,"epss":0.0045,"slug":"cve-2026-15679-hugging-face-pytorch-image-models-unsafe-checkpoint","title":"Hugging Face PyTorch Image Models unsafe checkpoint deserialization","severity":"high","exploited":false,"published_at":"2026-08-20T17:17:21.05+00:00","url":"https://junglewise.ai/threats/cve-2026-15679-hugging-face-pytorch-image-models-unsafe-checkpoint"},{"cve":"CVE-2026-9856","cvss":7.1,"epss":0.0046,"slug":"cve-2026-9856-hugging-face-transformers-path-traversal-in-save-pretrained","title":"A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. Th","severity":"high","exploited":false,"published_at":"2026-08-02T16:16:25.413+00:00","url":"https://junglewise.ai/threats/cve-2026-9856-hugging-face-transformers-path-traversal-in-save-pretrained"},{"cve":"CVE-2026-68770","cvss":9.8,"slug":"cve-2026-68770-hugging-face-sentence-transformers-code-execution-via-trust","title":"Hugging Face sentence-transformers code execution via trust_remote_code bypass","severity":"critical","exploited":false,"published_at":"2026-07-31T21:17:32.44+00:00","url":"https://junglewise.ai/threats/cve-2026-68770-hugging-face-sentence-transformers-code-execution-via-trust"},{"cve":"CVE-2026-66007","cvss":6.5,"epss":0.0079,"slug":"cve-2026-66007-hugging-face-datasets-path-traversal-in-folder-based-builders","title":"Hugging Face Datasets path traversal in folder-based builders","severity":"medium","exploited":false,"published_at":"2026-07-24T15:19:07.493+00:00","url":"https://junglewise.ai/threats/cve-2026-66007-hugging-face-datasets-path-traversal-in-folder-based-builders"},{"cve":"CVE-2026-65010","cvss":6.6,"slug":"cve-2026-65010-hugging-face-datasets-symlink-following-in-extractor-extract","title":"Hugging Face Datasets symlink following in Extractor.extract","severity":"medium","exploited":false,"published_at":"2026-07-23T19:17:03.89+00:00","url":"https://junglewise.ai/threats/cve-2026-65010-hugging-face-datasets-symlink-following-in-extractor-extract"},{"cve":"CVE-2026-65920","cvss":4.3,"slug":"cve-2026-65920-hugging-face-diffusers-path-traversal-in-get-checkpoint-shard","title":"Hugging Face Diffusers path traversal in _get_checkpoint_shard_files","severity":"medium","exploited":false,"published_at":"2026-07-23T18:17:02.427+00:00","url":"https://junglewise.ai/threats/cve-2026-65920-hugging-face-diffusers-path-traversal-in-get-checkpoint-shard"},{"cve":"CVE-2026-63086","cvss":8.6,"slug":"cve-2026-63086-hugging-face-text-generation-inference-ssrf-in-multimodal-chat","title":"Hugging Face text-generation-inference SSRF in multimodal chat endpoint","severity":"high","exploited":false,"published_at":"2026-07-16T17:16:58.553+00:00","url":"https://junglewise.ai/threats/cve-2026-63086-hugging-face-text-generation-inference-ssrf-in-multimodal-chat"},{"cve":"CVE-2026-45804","cvss":7.5,"epss":0.0037,"slug":"cve-2026-45804-hugging-face-diffusers-remote-code-execution-via-trust-remote","title":"Hugging Face Diffusers remote code execution via trust_remote_code bypass","severity":"high","exploited":false,"published_at":"2026-07-15T17:16:48.31+00:00","url":"https://junglewise.ai/threats/cve-2026-45804-hugging-face-diffusers-remote-code-execution-via-trust-remote"},{"cve":"CVE-2025-3933","cvss":3.1,"epss":0.0044,"slug":"cve-2025-3933-hugging-face-transformers-redos-in-donutprocessor","title":"PYSEC-2026-1977 - Transformers is vulnerable to ReDoS attack through its DonutProcessor class","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:57.564922+00:00","url":"https://junglewise.ai/threats/cve-2025-3933-hugging-face-transformers-redos-in-donutprocessor"},{"cve":"CVE-2024-3568","cvss":3,"epss":0.0208,"slug":"cve-2024-3568-hugging-face-transformers-deserialization-of-untrusted-data","title":"PYSEC-2026-1978 - Transformers Deserialization of Untrusted Data vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:37.939935+00:00","url":"https://junglewise.ai/threats/cve-2024-3568-hugging-face-transformers-deserialization-of-untrusted-data"},{"cve":"CVE-2026-5241","cvss":8,"epss":0.0094,"slug":"cve-2026-5241-hugging-face-transformers-rce-in-lightglue-model-loading","title":"Hugging Face Transformers RCE in LightGlue model loading","severity":"high","exploited":false,"published_at":"2026-06-03T14:16:46.337+00:00","url":"https://junglewise.ai/threats/cve-2026-5241-hugging-face-transformers-rce-in-lightglue-model-loading"},{"cve":"CVE-2026-4372","cvss":7.8,"epss":0.006,"slug":"cve-2026-4372-huggingface-transformers-remote-code-execution-via-config-json","title":"HuggingFace transformers remote code execution via config.json","severity":"high","exploited":false,"published_at":"2026-05-24T14:16:16.917+00:00","url":"https://junglewise.ai/threats/cve-2026-4372-huggingface-transformers-remote-code-execution-via-config-json"},{"cve":"CVE-2026-44827","cvss":8.8,"epss":0.007,"slug":"cve-2026-44827-hugging-face-diffusers-remote-code-execution-via-none-py-bypass","title":"Hugging Face Diffusers remote code execution via None.py bypass","severity":"high","exploited":false,"published_at":"2026-05-14T17:16:23.5+00:00","url":"https://junglewise.ai/threats/cve-2026-44827-hugging-face-diffusers-remote-code-execution-via-none-py-bypass"},{"cve":"CVE-2026-44513","cvss":8.8,"epss":0.0089,"slug":"cve-2026-44513-hugging-face-diffusers-remote-code-execution-in-diffusionpipeline","title":"Hugging Face Diffusers remote code execution in DiffusionPipeline","severity":"high","exploited":false,"published_at":"2026-05-14T17:16:22.903+00:00","url":"https://junglewise.ai/threats/cve-2026-44513-hugging-face-diffusers-remote-code-execution-in-diffusionpipeline"},{"cve":"CVE-2024-11393","cvss":8.8,"epss":0.0307,"slug":"cve-2024-11393-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in model parsing","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11393-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2024-11394","cvss":8.8,"epss":0.0257,"slug":"cve-2024-11394-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in model files","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11394-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2024-11392","cvss":7.5,"epss":0.0726,"slug":"cve-2024-11392-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in config handling","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11392-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2023-6730","cvss":3.1,"epss":0.0093,"slug":"cve-2023-6730-hugging-face-transformers-deserialization-of-untrusted-data","title":"PYSEC-2023-300 - Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.","severity":"low","exploited":false,"published_at":"2023-12-19T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-6730-hugging-face-transformers-deserialization-of-untrusted-data"},{"cve":"CVE-2023-2800","cvss":3.1,"epss":0.0029,"slug":"cve-2023-2800-hugging-face-transformers-insecure-temporary-file-in-model-loading","title":"PYSEC-2023-299 - Insecure Temporary File in GitHub repository huggingface/transformers prior to 4.30.0.","severity":"low","exploited":false,"published_at":"2023-05-18T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-2800-hugging-face-transformers-insecure-temporary-file-in-model-loading"}],"vendor":{"hub":true,"name":"Hugging Face","slug":"hugging-face","homepage":"https://huggingface.co","description":"Company providing machine learning models, datasets, and tools for natural language processing and computer vision.","url":"https://junglewise.ai/threats/vendors/hugging-face"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-27","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-68770","cvss":9.8,"slug":"cve-2026-68770-hugging-face-sentence-transformers-code-execution-via-trust","title":"Hugging Face sentence-transformers code execution via trust_remote_code bypass","severity":"critical","exploited":false,"published_at":"2026-07-31T21:17:32.44+00:00","url":"https://junglewise.ai/threats/cve-2026-68770-hugging-face-sentence-transformers-code-execution-via-trust"},{"cve":"CVE-2024-11393","cvss":8.8,"epss":0.0307,"slug":"cve-2024-11393-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in model parsing","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11393-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2024-11394","cvss":8.8,"epss":0.0257,"slug":"cve-2024-11394-hugging-face-transformers-deserialization-of-untrusted-data-in","title":"Hugging Face Transformers deserialization of untrusted data in model files","severity":"high","exploited":false,"published_at":"2024-11-23T03:31:58+00:00","url":"https://junglewise.ai/threats/cve-2024-11394-hugging-face-transformers-deserialization-of-untrusted-data-in"},{"cve":"CVE-2026-44513","cvss":8.8,"epss":0.0089,"slug":"cve-2026-44513-hugging-face-diffusers-remote-code-execution-in-diffusionpipeline","title":"Hugging Face Diffusers remote code execution in DiffusionPipeline","severity":"high","exploited":false,"published_at":"2026-05-14T17:16:22.903+00:00","url":"https://junglewise.ai/threats/cve-2026-44513-hugging-face-diffusers-remote-code-execution-in-diffusionpipeline"},{"cve":"CVE-2026-44827","cvss":8.8,"epss":0.007,"slug":"cve-2026-44827-hugging-face-diffusers-remote-code-execution-via-none-py-bypass","title":"Hugging Face Diffusers remote code execution via None.py bypass","severity":"high","exploited":false,"published_at":"2026-05-14T17:16:23.5+00:00","url":"https://junglewise.ai/threats/cve-2026-44827-hugging-face-diffusers-remote-code-execution-via-none-py-bypass"},{"cve":"CVE-2026-63086","cvss":8.6,"slug":"cve-2026-63086-hugging-face-text-generation-inference-ssrf-in-multimodal-chat","title":"Hugging Face text-generation-inference SSRF in multimodal chat endpoint","severity":"high","exploited":false,"published_at":"2026-07-16T17:16:58.553+00:00","url":"https://junglewise.ai/threats/cve-2026-63086-hugging-face-text-generation-inference-ssrf-in-multimodal-chat"},{"cve":"CVE-2026-5241","cvss":8,"epss":0.0094,"slug":"cve-2026-5241-hugging-face-transformers-rce-in-lightglue-model-loading","title":"Hugging Face Transformers RCE in LightGlue model loading","severity":"high","exploited":false,"published_at":"2026-06-03T14:16:46.337+00:00","url":"https://junglewise.ai/threats/cve-2026-5241-hugging-face-transformers-rce-in-lightglue-model-loading"},{"cve":"CVE-2026-4372","cvss":7.8,"epss":0.006,"slug":"cve-2026-4372-huggingface-transformers-remote-code-execution-via-config-json","title":"HuggingFace transformers remote code execution via config.json","severity":"high","exploited":false,"published_at":"2026-05-24T14:16:16.917+00:00","url":"https://junglewise.ai/threats/cve-2026-4372-huggingface-transformers-remote-code-execution-via-config-json"},{"cve":"CVE-2026-15679","cvss":7.8,"epss":0.0045,"slug":"cve-2026-15679-hugging-face-pytorch-image-models-unsafe-checkpoint","title":"Hugging Face PyTorch Image Models unsafe checkpoint deserialization","severity":"high","exploited":false,"published_at":"2026-08-20T17:17:21.05+00:00","url":"https://junglewise.ai/threats/cve-2026-15679-hugging-face-pytorch-image-models-unsafe-checkpoint"},{"cve":"CVE-2026-80047","cvss":7.8,"epss":0.001,"slug":"cve-2026-80047-hugging-face-transformers-arbitrary-file-write-via-load-custom","title":"Hugging Face Transformers arbitrary file write via load_custom_generate","severity":"high","exploited":false,"published_at":"2026-09-01T14:17:41.943+00:00","url":"https://junglewise.ai/threats/cve-2026-80047-hugging-face-transformers-arbitrary-file-write-via-load-custom"}],"generated_at":"2026-09-26T13:07:00.120236+00:00","technologies":[{"name":"Hugging Face Transformers","slug":"transformers","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/transformers"},{"name":"Hugging Face Diffusers","slug":"diffusers","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/diffusers"}]}