CVE-2026-4963 identifies a code injection vulnerability in huggingface smolagents version 1.25.0.dev0, specifically within the `local_python_executor.py` component, stemming from an incomplete fix for CVE-2025-9959. This medium-severity flaw (CVSS 6.3) can be exploited remotely with low complexity, though it requires user interaction and results in low impacts to confidentiality, integrity, and availability. Public exploit code is available, and the vendor has not responded to disclosure. However, there is no indication of active exploitation, and community discussion remains minimal with only one mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.25.0CPE matchmatch criteria | cpe:2.3:a:huggingface:smolagents:1.25.0:dev0:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.