ZDI-25-1148: (0Day) Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint. The specific flaw exists within the convertconfig function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-14927.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-1148?
ZDI-25-1148 is classified as a high severity vulnerability allowing remote code execution.
How do I fix ZDI-25-1148?
To mitigate ZDI-25-1148, avoid using unverified or malicious checkpoints when using Hugging Face Transformers.
Who is affected by ZDI-25-1148?
ZDI-25-1148 affects installations of Hugging Face Transformers that allow users to convert checkpoints.
Is user interaction necessary to exploit ZDI-25-1148?
Yes, user interaction is required as the target must convert a malicious checkpoint to exploit ZDI-25-1148.
What type of vulnerability is ZDI-25-1148?
ZDI-25-1148 is a remote code execution vulnerability found in Hugging Face Transformers.