First published: Tue Dec 19 2023(Updated: )
Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
pip/transformers | <4.36.0 | 4.36.0 |
Hugging Face | <4.36.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6730 has been rated with a high severity due to the deserialization of untrusted data vulnerability.
To fix CVE-2023-6730, you should upgrade the huggingface transformers library to version 4.36.0 or later.
CVE-2023-6730 affects any system using versions of the huggingface transformers library prior to 4.36.0.
If exploited, CVE-2023-6730 could allow malicious actors to execute arbitrary code, leading to potential data breaches or system compromises.
There are no officially recommended workarounds for CVE-2023-6730, and upgrading to a patched version is strongly advised.