Skip to content
TransformersGHSA-37q5-v5qm-c9v8

Transformers Deserialization of Untrusted Data vulnerability

Low3.4CVE-2024-3568 · Published Apr 10, 2024 · updated Jul 7, 2026

The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreTrainedModel()` class. Attackers can execute arbitrary code and commands by crafting a malicious serialized payload, exploiting the use of `pickle.load()` on data from potentially untrusted sources. This vulnerability allows for remote code execution (RCE) by deceiving victims into loading a seemingly harmless checkpoint during a normal training process, thereby enabling attackers to execute arbitrary code on the targeted machine.

GitHub advisory

Affected versions

PackageAffectedFixed in
transformers
PyPI
< 4.38.04.38.0
Details and references

More Transformers advisories

All Transformers
Advisory
Deserialization of Untrusted Data in Hugging Face Transformers
High8.8Nov 23, 2024
Deserialization of Untrusted Data in Hugging Face Transformers
High7.5Nov 23, 2024
Deserialization of Untrusted Data in Hugging Face Transformers
High8.8Nov 23, 2024
transformers has a Deserialization of Untrusted Data vulnerability
High7.8Dec 20, 2023
transformers has a Deserialization of Untrusted Data vulnerability
Critical9.0Dec 19, 2023
transformers has Insecure Temporary File
Medium4.7May 18, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.