A critical vulnerability in the Hugging Face Transformers library (CVE-2026-80047) allows unauthorized code to be written to local disks without user consent. This affects library versions 4.49.0 through 5.8.1, enabling attackers to cache malicious code when users load compromised models. While no exploitation has been confirmed, developers are at risk, as previously cached unauthorized code may execute later. No patch is currently available; users are advised to avoid untrusted repositories and inspect module cache regularly.
CVE-2026-80047: Hugging Face Transformers Library Vulnerability
CyberSIXT Evidence Panel
Article by CyberSIXT