Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-11392

39
FAUCET Score

CVE-2024-11392 is a critical remote code execution (RCE) vulnerability affecting Hugging Face Transformers, specifically within the MobileViTV2 configuration handling. This flaw, stemming from improper validation leading to deserialization of untrusted data, allows attackers to execute arbitrary code on a victim's system if they interact with a malicious page or file. With a CVSS score of 8.8 (High) and a FAUCET Risk Score of 98/100, the vulnerability presents a significant risk, requiring user interaction but offering high impact across confidentiality, integrity, and availability. While not yet in CISA's KEV catalog and showing minimal community discussion, an exploit (EDB-52227) is publicly available on ExploitDB, indicating a potential for active exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.48.0CPE matchmatch criteria
cpe:2.3:a:huggingface:transformers:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.6
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
7.14%
Probability of exploitation in next 30 days
EPSS Percentile
93.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-52227 · Apr 16, 2025
This CVE's current EPSS score of 0.0714 is in the 93rd percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

pippatch availablevia ghsa
Product: transformersFixed in: 4.48.0

Vendor Advisories (2)

pipGHSA-qxrp-vhvm-j765high

Deserialization of Untrusted Data in Hugging Face Transformers

Nov 23, 2024
redhatCVE-2024-11392Important

transformers: Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability

Nov 22, 2024

References

zerodayinitiative.com / advisories/ZDI-24-1513
Third Party AdvisoryVDB Entry