
Hugging Face Transformers Flaw Writes Attacker-Controlled Python Code Before User Consent
A newly disclosed vulnerability in the Hugging Face Transformers library can cause attacker-controlled Python code to be written to a local system before a user decides whether to trust and execute remote code. Tracked as CVE-2026-80047 and documented in CERT Coordination Center Vulnerability Note VU#456290, the issue affects Hugging Face Transformers versions 4.49.0 through 5.8.1. […]
The post Hugging Face Transformers Flaw Writes Attacker-Controlled Python Code Before User Consent appeared first on Cyber Security News.