Skip to content

Hugging Face security advisories

83 advisories across Transformers, Gradio

Company profile
DateAdvisory
Aug 2Transformers save_pretrained path traversal allows arbitrary file writes through chat template names
CVE-2026-9856TransformersHigh7.1fixed in 5.10.0
Jul 1Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory traversal sequences or absolute paths. Attackers can provide c
CVE-2026-49119GradioHigh7.5fixed in 6.16.0
Jun 4Gradio: Audio cache key ignores metadata when saving numpy audio outputs
CVE-2026-10783GradioLow2.5fixed in 6.15.1
Jun 3huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
CVE-2026-5241TransformersHigh8.0fixed in 5.5.0
May 27Gradio contains a cookie injection vulnerability
CVE-2026-48545GradioHigh6.8fixed in 6.15.0
May 26HuggingFace transformers vulnerable to remote code execution
CVE-2026-4372TransformersHigh7.8fixed in 5.3.0
Apr 7HuggingFace Transformers allows for arbitrary code execution in the `Trainer` class
CVE-2026-1839TransformersMedium6.5fixed in 5.0.0rc3
Mar 1Gradio has SSRF via Malicious `proxy_url` Injection in `gr.load()` Config Processing
CVE-2026-28416GradioHigh8.2fixed in 6.6.0
Mar 1Gradio has an Open Redirect in its OAuth Flow
CVE-2026-28415GradioMedium4.3fixed in 6.6.0
Mar 1Gradio is Vulnerable to Absolute Path Traversal on Windows with Python 3.13+
CVE-2026-28414GradioHigh7.5fixed in 6.7.0
Mar 1Gradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session Secret
CVE-2026-27167GradioLow0.0fixed in 6.6.0
Dec 232025Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the targ
CVE-2025-14928TransformersHigh7.8no fix yet
Dec 232025Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vuln
CVE-2025-14929TransformersHigh7.8no fix yet
Dec 232025Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the ta
CVE-2025-14930TransformersHigh7.8no fix yet
Dec 232025Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in
CVE-2025-14920TransformersHigh7.8no fix yet
Dec 232025Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerabilit
CVE-2025-14921TransformersHigh7.8no fix yet
Dec 232025Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in th
CVE-2025-14924TransformersHigh7.8no fix yet
Dec 232025Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target
CVE-2025-14926TransformersHigh7.8no fix yet
Dec 232025Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the targe
CVE-2025-14927TransformersHigh7.8no fix yet
Sep 232025Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
CVE-2025-6921TransformersMedium5.3fixed in 4.53.0
Sep 142025Hugging Face Transformers library has Regular Expression Denial of Service
CVE-2025-6051TransformersMedium5.3fixed in 4.53.0
Sep 122025Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
CVE-2025-6638TransformersMedium5.3fixed in 4.53.0
Aug 62025Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2025-5197TransformersMedium5.3fixed in 4.53.0
Jul 112025Transformers is vulnerable to ReDoS attack through its DonutProcessor class
CVE-2025-3933TransformersMedium5.3fixed in 4.52.1
Jul 72025Transformers vulnerable to ReDoS attack through its SETTING_RE variable
CVE-2025-3262TransformersMedium5.3fixed in 4.51.0
Jul 72025Transformers vulnerable to ReDoS attack through its get_imports() function
CVE-2025-3264TransformersMedium5.3fixed in 4.51.0
Jul 72025Transformers's Improper Input Validation vulnerability can be exploited through username injection
CVE-2025-3777TransformersLow3.5fixed in 4.52.1
Jul 72025Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking
CVE-2025-3263TransformersMedium5.3fixed in 4.51.0
May 292025Gradio Allows Unauthorized File Copy via Path Manipulation
CVE-2025-48889GradioMedium5.3fixed in 5.31.0
May 292025Gradio CORS Origin Validation Bypass Vulnerability
CVE-2025-5320GradioLow3.7no fix yet
May 192025Hugging Face Transformers Regular Expression Denial of Service
CVE-2025-2099TransformersMedium5.3fixed in 4.50.0
Apr 292025Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2025-1194TransformersMedium4.3fixed in 4.50.0
Mar 202025Transformers Regular Expression Denial of Service (ReDoS) vulnerability
CVE-2024-12720TransformersMedium5.3fixed in 4.48.0
Mar 202025Gradio DOS in multipart boundry while uploading the file
CVE-2024-8966GradioHigh7.5no fix yet
Mar 202025Gradio Vulnerable to Open Redirect
CVE-2024-8021GradioMedium5.4no fix yet
Mar 202025Gradio Path Traversal vulnerability
CVE-2024-12217GradioMedium5.3no fix yet
Mar 202025Gradio Vulnerable to Denial of Service (DoS) via Crafted Zip Bomb
CVE-2024-10569GradioHigh7.5no fix yet
Mar 202025Gradio Vulnerable to Arbitrary File Deletion
CVE-2024-10648GradioHigh8.2no fix yet
Mar 202025Gradio Vulnerable to Denial of Service (DoS) via Crafted HTTP Request
CVE-2024-10624GradioHigh7.5no fix yet
Jan 142025Gradio Blocked Path ACL Bypass Vulnerability
CVE-2025-23042GradioCriticalfixed in 5.11.0
Nov 232024Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11394TransformersHigh8.8fixed in 4.48.0
Nov 232024Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11392TransformersHigh7.5fixed in 4.48.0
Nov 232024Deserialization of Untrusted Data in Hugging Face Transformers
CVE-2024-11393TransformersHigh8.8fixed in 4.48.0
Nov 62024Gradio vulnerable to arbitrary file read with File and UploadButton components
CVE-2024-51751GradioMedium0.0fixed in 5.5.0
Nov 52024gradio Server Side Request Forgery vulnerability
CVE-2024-48052GradioMedium6.5no fix yet
Oct 102024Gradio's dropdown component pre-process step does not limit the values to those in the dropdown list
GHSA-26jh-r8g2-6fprGradioLow5.3fixed in 5.0.0
Oct 102024Gradio has an XSS on every Gradio server via upload of HTML files, JS files, or SVG files
CVE-2024-47872GradioMedium5.4fixed in 5.0.0
Oct 102024Gradio uses insecure communication between the FRP client and server
CVE-2024-47871GradioHigh8.1fixed in 5.0.0
Oct 102024Gradio has a race condition in update_root_in_config may redirect user traffic
CVE-2024-47870GradioHigh7.0fixed in 5.0.0
Oct 102024Gradio performs a non-constant-time comparison when comparing hashes
CVE-2024-47869GradioMedium3.7fixed in 4.44.0
Oct 102024Gradio has several components with post-process steps allow arbitrary file leaks
CVE-2024-47868GradioMedium5.3fixed in 5.0.0
Oct 102024Gradio lacks integrity checking on the downloaded FRP client
CVE-2024-47867GradioHigh7.5fixed in 5.0.0
Oct 102024In Gradio, the `enable_monitoring` flag set to `False` does not disable monitoring
CVE-2024-47168GradioLow4.3fixed in 4.44.0
Oct 102024Gradio vulnerable to SSRF in the path parameter of /queue/join
CVE-2024-47167GradioMedium7.2fixed in 5.0.0
Oct 102024Gradio has a one-level read path traversal in `/custom_component`
CVE-2024-47166GradioMedium5.3fixed in 4.44.0
Oct 102024Gradio's CORS origin validation accepts the null origin
CVE-2024-47165GradioMedium5.4fixed in 5.0.0
Oct 102024Gradio's `is_in_or_equal` function may be bypassed
CVE-2024-47164GradioMedium6.5fixed in 5.0.0
Oct 102024Gradios's CORS origin validation is not performed when the request has a cookie
CVE-2024-47084GradioHigh8.8fixed in 4.44.0
Sep 252024Gradio allows users to access arbitrary files
CVE-2024-1728GradioCritical8.1fixed in 4.19.2
Jul 12024Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes this because the report is about a user attacking himself.
CVE-2024-39236GradioCritical9.8no fix yet

The newest 60. Each project page has the full list.

About Hugging Face

Hugging Face, Inc., is an American company based in New York City that develops computation tools for building applications using machine learning. Hugging Face's Transformers library is built for natural language processing applications.

Elsewhere on fru.dev: Acquisitions · Paydays · Releases · Repos · Trending

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.