Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 04 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Huggingface
Huggingface transformers |
|
| CPEs | cpe:2.3:a:huggingface:transformers:5.2.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Huggingface
Huggingface transformers |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 04 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 03 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when loading a LightGlue model using `AutoModel.from_pretrained()` with `trust_remote_code=False`, the `LightGlueConfig` reads the `trust_remote_code` value from the untrusted `config.json` file and propagates it into nested `AutoConfig.from_pretrained()` calls. This results in the execution of attacker-provided Python modules, even when the victim explicitly disables remote code execution. The vulnerability poses a high risk for environments such as API inference servers, research notebooks, CI/CD pipelines, and model evaluation workers, potentially leading to credential theft, lateral movement, or persistence/backdoor deployment. | |
| Title | Policy Bypass in LightGlue Nested Config Resolution in huggingface/transformers | |
| Weaknesses | CWE-829 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2026-06-03T15:45:36.684Z
Reserved: 2026-03-31T14:26:14.353Z
Link: CVE-2026-5241
Updated: 2026-06-03T15:45:33.083Z
Status : Analyzed
Published: 2026-06-03T14:16:46.337
Modified: 2026-06-04T18:54:28.290
Link: CVE-2026-5241
OpenCVE Enrichment
Updated: 2026-06-05T08:30:24Z