Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Huggingface

First CVE: May 18, 2023Active for: 3 yearsTotal CVEs: 38
58.1
VTI Score
TOP TARGET

Huggingface maintains a modestly sized but strategically prominent portfolio of machine-learning and AI tooling libraries, including Transformers, SmoLAgents, and LeRobot, that are embedded across research and production pipelines in the broader AI ecosystem. Despite a narrow product line, the vendor's visibility in the landscape reflects the widespread adoption of its frameworks for model training, inference, and deployment. Vulnerabilities affecting Huggingface skew toward serious outcomes, with an elevated share reaching critical severity; the recurring weakness classes—including untrusted deserialization, code injection, inefficient regex patterns, and input-validation flaws—reflect the inherent risks of accepting and processing untrusted model artifacts, user-supplied code, and dynamic expressions within a Python-centric environment. Defenders should treat this vendor's security updates as priority within the AI development and deployment pipeline, particularly where model weights and inference code flow through untrusted sources; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
38
Total CVEs
More Total CVEs than 98% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Huggingface over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 18, 2023
3 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-25874CRITICAL
LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticate
Apr 23, 20269.850NONO
CVE-2025-5120CRITICAL
A sandbox escape vulnerability was identified in huggingface/smolagents version 1.14.0, allowing attackers to bypass the restricted execution environment and achieve remote code ex
Jul 27, 202510.044NONO
CVE-2026-5241CRITICAL
A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model
Jun 3, 20269.639NONO
CVE-2024-11392HIGH
Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on
Nov 22, 20248.839NOYES
CVE-2026-4372HIGH
A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft
May 24, 20267.838NONO
CVE-2026-44513HIGH
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution
May 14, 20268.835NONO
CVE-2026-2654CRITICAL
A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExecutor. Executing a manipulation
Feb 18, 20269.834NONO
CVE-2026-44827HIGH
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loadin
May 14, 20268.833NONO
CVE-2026-4963CRITICAL
A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the file src/smolagents/local_pyth
Mar 27, 202610.031NONO
CVE-2024-3568CRITICAL
The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreT
Apr 10, 20249.630NONO
View all 38 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products38 CVEs
24%
58%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local12 (31.6%)
Network26 (68.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (97.4%)
High1 (2.6%)
Unknown0 (0.0%)
User Interaction
None16 (42.1%)
Unknown0 (0.0%)
Required22 (57.9%)
Privileges Required
Low3 (7.9%)
High0 (0.0%)
None35 (92.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.6% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Huggingface.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Huggingface — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Huggingface's Products

View all 5 CNAs →

Top CWEs