Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Huggingface

10 known vulnerabilities

2
CRITICAL
5
HIGH
3
MEDIUM

Top Products

diffusers 3 transformers 3 smolagents 2 datasets 1 lerobot 1
10 CVEs
6.5
CVE-2026-66007

Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builder

7.5
CVE-2026-45804

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretraine

9.6
CVE-2026-5241

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-control

7.8
CVE-2026-4372

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to v

8.8
CVE-2026-44827

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execut

8.8
CVE-2026-44513

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPip

9.8
CVE-2026-25874

LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.load

7.8
CVE-2026-1839

A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code

6.3
CVE-2026-4963

A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evalu

6.3
CVE-2026-2654

A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of

Frequently Asked Questions

How many CVEs affect Huggingface?

Huggingface has 10 CVE records in our database, including 2 critical and 5 high severity vulnerabilities.

What are the most severe Huggingface vulnerabilities?

Huggingface has 2 critical severity (CVSS 9.0+) and 5 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Huggingface vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Huggingface products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Huggingface Vulnerabilities

CyberStrike scans your infrastructure for Huggingface vulnerabilities and provides real-time remediation guidance.

Get Started