Huggingface maintains a modestly sized but strategically prominent portfolio of machine-learning and AI tooling libraries, including Transformers, SmoLAgents, and LeRobot, that are embedded across research and production pipelines in the broader AI ecosystem. Despite a narrow product line, the vendor's visibility in the landscape reflects the widespread adoption of its frameworks for model training, inference, and deployment. Vulnerabilities affecting Huggingface skew toward serious outcomes, with an elevated share reaching critical severity; the recurring weakness classes—including untrusted deserialization, code injection, inefficient regex patterns, and input-validation flaws—reflect the inherent risks of accepting and processing untrusted model artifacts, user-supplied code, and dynamic expressions within a Python-centric environment. Defenders should treat this vendor's security updates as priority within the AI development and deployment pipeline, particularly where model weights and inference code flow through untrusted sources; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Huggingface over time
Signals from CVEs in this vendor scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25874CRITICAL LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticate | Apr 23, 2026 | 9.8 | 50 | NO | NO |
CVE-2025-5120CRITICAL A sandbox escape vulnerability was identified in huggingface/smolagents version 1.14.0, allowing attackers to bypass the restricted execution environment and achieve remote code ex | Jul 27, 2025 | 10.0 | 44 | NO | NO |
CVE-2026-5241CRITICAL A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model | Jun 3, 2026 | 9.6 | 39 | NO | NO |
CVE-2024-11392HIGH Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on | Nov 22, 2024 | 8.8 | 39 | NO | YES |
CVE-2026-4372HIGH A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft | May 24, 2026 | 7.8 | 38 | NO | NO |
CVE-2026-44513HIGH Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution | May 14, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-2654CRITICAL A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExecutor. Executing a manipulation | Feb 18, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-44827HIGH Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loadin | May 14, 2026 | 8.8 | 33 | NO | NO |
CVE-2026-4963CRITICAL A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the file src/smolagents/local_pyth | Mar 27, 2026 | 10.0 | 31 | NO | NO |
CVE-2024-3568CRITICAL The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreT | Apr 10, 2024 | 9.6 | 30 | NO | NO |
Signals from CVEs in this vendor scope (38 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Huggingface.
Media articles that mention a CVE ID that affects a product developed by Huggingface — matched by CVE ID, not by vendor name.