System running
Last check: 2026-09-29 02:26:23 | Auto-updates every hour
756 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-CVE-2026-4372

Severity
UNKNOWN
CVSS Score
0.0
Description

A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attacker-controlled HuggingFace Hub repository ID. When a victim loads this model using the standard `AutoModelForCausalLM.from_pretrained()` API, the library downloads and executes arbitrary Python code from the attacker's re...

PoCs for CVE-CVE-2026-4372

hf-kernels-rce-proof
RCE Python 0
AUTHENSOR 2026-09-16
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources