CVE-2026-5241 PUBLISHED

Policy Bypass in LightGlue Nested Config Resolution in huggingface/transformers

Assigner: @huntr_ai
Reserved: 31.03.2026 Published: 03.06.2026 Updated: 03.06.2026

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the trust_remote_code parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when loading a LightGlue model using AutoModel.from_pretrained() with trust_remote_code=False, the LightGlueConfig reads the trust_remote_code value from the untrusted config.json file and propagates it into nested AutoConfig.from_pretrained() calls. This results in the execution of attacker-provided Python modules, even when the victim explicitly disables remote code execution. The vulnerability poses a high risk for environments such as API inference servers, research notebooks, CI/CD pipelines, and model evaluation workers, potentially leading to credential theft, lateral movement, or persistence/backdoor deployment.

Metrics

CVSS Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
CVSS Score: 8

Product Status

Vendor huggingface
Product huggingface/transformers
Versions
  • affected from unspecified to 5.5.0 (excl.)

References

Problem Types

  • CWE-829 Inclusion of Functionality from Untrusted Control Sphere CWE