← العودة للجدول
CVE-2026-5241
CVE-2026-5241 — VulnCheck: A vulnerability in the LightGlue model loading path of huggingface/tra
📅 2026-06-03
🟠 High 🔥 No VulnCheck Exploit Malware CVSS 8

📋 الوصف الكامل

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when lo

💻 الأنظمة المتأثرة

Python

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-5241

📡 المصدر

VulnCheck

✅ الحلول والتخفيف

Update to v5.2.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←