CVE-2024-11392 is a critical remote code execution (RCE) vulnerability affecting Hugging Face Transformers, specifically within the MobileViTV2 configuration handling. This flaw, stemming from improper validation leading to deserialization of untrusted data, allows attackers to execute arbitrary code on a victim's system if they interact with a malicious page or file. With a CVSS score of 8.8 (High) and a FAUCET Risk Score of 98/100, the vulnerability presents a significant risk, requiring user interaction but offering high impact across confidentiality, integrity, and availability. While not yet in CISA's KEV catalog and showing minimal community discussion, an exploit (EDB-52227) is publicly available on ExploitDB, indicating a potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.48.0CPE matchmatch criteria | cpe:2.3:a:huggingface:transformers:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.