CVE-2023-6730: Deserialization of Untrusted Data in huggingface/transformers
Published Dec 19, 2023
·Updated
Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
Affected Software
2 affected componentsFixes available
pip/transformers<4.36.0
4.36.0
huggingface transformers<4.36.0
Remediation
Event History
Dec 19, 2023
CVE Published
12:11 PM
Data Sourced
12:11 PM
DescriptionSeverityWeakness
Advisory Published
03:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-6730?
CVE-2023-6730 has been rated with a high severity due to the deserialization of untrusted data vulnerability.
2
How do I fix CVE-2023-6730?
To fix CVE-2023-6730, you should upgrade the huggingface transformers library to version 4.36.0 or later.
3
What types of systems are affected by CVE-2023-6730?
CVE-2023-6730 affects any system using versions of the huggingface transformers library prior to 4.36.0.
4
What could happen if CVE-2023-6730 is exploited?
If exploited, CVE-2023-6730 could allow malicious actors to execute arbitrary code, leading to potential data breaches or system compromises.
5
Is there a workaround for CVE-2023-6730 if an upgrade cannot be applied?
There are no officially recommended workarounds for CVE-2023-6730, and upgrading to a patched version is strongly advised.