CVE-2024-11393 is a remote code execution vulnerability affecting Hugging Face Transformers, specifically within the MaskFormer model's deserialization process. This flaw, stemming from improper validation of user-supplied data, allows an attacker to execute arbitrary code on a victim's system if they interact with a malicious page or file. Rated with a CVSS score of 8.8 (HIGH), it requires user interaction but can lead to full compromise (confidentiality, integrity, and availability). While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been observed, its high EPSS score and FAUCET Risk Score indicate significant potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.48.0CPE matchmatch criteria | cpe:2.3:a:huggingface:transformers:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.