FAIL › dossier
huggingface
VENDOR· dossier confidence 50%
Hugging Face is a major AI infrastructure provider that has recently suffered critical security failures, including an RCE0day and unsafe deserialization vulnerabilities, alongside a breach of pre-release models affecting partners like OpenAI.
PROFILE
CategoryAI/ML InfrastructureWhat they doHugging Face provides open-source machine learning models, datasets, and tools for developers and enterprises.
SECURITY POSTURE
The company has suffered critical vulnerabilities including an RCE0day in model loading and unsafe deserialization, indicating gaps in input validation and secure deserialization practices.
Notable failures
- CVE-2026-5241 RCE0day in LightGlue model loading
- CVE-2026-25874 unsafe deserialization in LeRobot
- Pre-release model breach impacting OpenAI
Patterns: unsafe deserialization in ML libraries; RCE via model loading paths
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-06-03 | CVE-2026-5241 | critical | A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remo |
| 2026-04-23 | CVE-2026-25874 | critical | CVE-2026-25874: LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the as |
Open questions: Exact impact of the pre-release model breach on OpenAI's data · Whether CVE-2026-25874 was patched before exploitation
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-22 04:16:52.907938+00:00