During Model Initialization Remote Code Execution Vulnerability
Evidence indicates that During Model Initialization is affected by remote code execution.
STABLE
What Happened
Evidence indicates that During Model Initialization is affected by remote code execution.
Why This Matters
The evidence matters to defenders using During Model Initialization because it could let an attacker run code in affected environments.
Recommended Action
No confirmed vendor remediation is available in the current evidence. Confirm whether During Model Initialization is present in your environment and review the affected configuration.
Exposure
Exposure unknown
Jun 03, 2026 21:00
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
Jun 03, 2026 21:00BugSkan first recorded this incident.
-
huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
Jun 03, 2026 21:00GitHub Advisory Database · Vulnerability
Sources
GitHub Advisory Database · Jun 03, 2026 21:00
A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when loading a LightGlue model using `AutoModel.from_pretrained()` with `trust_remote_code=False`, the `LightGlueConfig` reads the `trust_remote_code` value from the untrusted `config.json` file and propagates it into nested `AutoConfig.from_pretrained()` calls. This results in the execution of attacker-provided Python modules, even when the victim explicitly disables remote code execution. The vulnerability poses a high risk for environments such as API inference servers, research notebooks, CI/CD pipelines, and model evaluation workers, potentially leading to credential theft, lateral movement, or persistence/backdoor deployment.
Open publisher sourceMy Interests Match
Create an account to see which incidents overlap with your interests.