CVE-2025-14922 is a critical remote code execution vulnerability in Hugging Face Diffusers, specifically affecting the CogView4 component. This flaw stems from improper validation during checkpoint parsing, leading to deserialization of untrusted data. A successful exploit, requiring user interaction like visiting a malicious page, allows an attacker to execute arbitrary code with high impact on confidentiality, integrity, and availability. While rated High severity (CVSS 7.8), there is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Hugging Face | Diffusers | 22a452a526660363b57216cd011ce75345382d02CNA affecteddefault unknown |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.