Untrusted Data Remote Code Execution Vulnerability
Evidence indicates that Untrusted Data is affected by remote code execution.
What Happened
Evidence indicates that Untrusted Data is affected by remote code execution.
Why This Matters
The evidence matters to defenders using Untrusted Data because it could let an attacker run code in affected environments.
Recommended Action
No confirmed vendor remediation is available in the current evidence. Confirm whether Untrusted Data is present in your environment and review the affected configuration.
Exposure
Exposure unknown
Apr 11, 2024 00:00
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
Apr 11, 2024 00:00BugSkan first recorded this incident.
-
Transformers Deserialization of Untrusted Data vulnerability
Apr 11, 2024 00:00OSV.dev · Vulnerability
Sources
OSV.dev · Apr 11, 2024 00:00
The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreTrainedModel()` class. Attackers can execute arbitrary code and commands by crafting a malicious serialized payload, exploiting the use of `pickle.load()` on data from potentially untrusted sources. This vulnerability allows for remote code execution (RCE) by deceiving victims into loading a seemingly harmless checkpoint during a normal training process, thereby enabling attackers to execute arbitrary code on the targeted machine.
Open publisher sourceMy Interests Match
Create an account to see which incidents overlap with your interests.