<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:14:42.024340+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-mlx-lm-cve-2025-14927</id>
    <title>BREW-mlx-lm-CVE-2025-14927</title>
    <updated>2026-10-02T16:14:42.218742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: mlx-lm</p>
<p>Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.</p>
<p>The specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.</p>
<p>. Was ZDI-CAN-28252.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-mlx-lm-cve-2025-14927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-264351</id>
    <title>EUVD-2026-264351</title>
    <updated>2026-10-02T16:14:42.218825+00:00</updated>
    <content>EUVD-2026-264351</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-264351"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-14927</id>
    <title>fkie_cve-2025-14927</title>
    <updated>2026-10-02T16:14:42.218842+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.</p>
<p>The specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.</p>
<p>. Was ZDI-CAN-28252.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-14927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jpvf-f2r6-62cq</id>
    <title>GHSA-jpvf-f2r6-62cq</title>
    <updated>2026-10-02T16:14:42.218870+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.</p>
<p>The specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.</p>
<p>. Was ZDI-CAN-28252.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jpvf-f2r6-62cq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2025-215</id>
    <title>PYSEC-2025-215</title>
    <updated>2026-10-02T16:14:42.218889+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: transformers</p>
<p>Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.</p>
<p>The specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.</p>
<p>. Was ZDI-CAN-28252.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2025-215"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:30078</id>
    <title>RHSA-2026:30078 — Red Hat Security Advisory: Red Hat AI Inference Server Model Optimization Tools 3.3.5 (CUDA)</title>
    <updated>2026-10-02T16:14:42.218911+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>transformers: code execution when converting a malicious SEW model checkpoint transformers: code execution when converting a malicious SEW-D model checkpoint transformers: code execution when converting a malicious HuBERT model checkpoint transformers: code execution when processing a malicious GLM4 model file libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication OpenEXR: OpenEXR: Arbitrary code execution and information disclosure via crafted EXR file vim: arbitrary command execution via modeline sandbox bypass OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode libsndfile: integer overflow in ima_reader_init() jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers jq: jq: Denial of Service via crafted JSON object causing hash collisions urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:30078"/>
  </entry>
</feed>
