<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:33:20 +0000</lastBuildDate>
    <item>
      <title>BREW-mlx-lm-CVE-2025-14927</title>
      <link>https://cve.radiocsirt.org/vuln/brew-mlx-lm-cve-2025-14927</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mlx-lm&lt;/p&gt;
&lt;p&gt;Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.&lt;/p&gt;
&lt;p&gt;. Was ZDI-CAN-28252.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mlx-lm&lt;/p&gt;
&lt;p&gt;Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.&lt;/p&gt;
&lt;p&gt;. Was ZDI-CAN-28252.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-mlx-lm-cve-2025-14927</guid>
    </item>
    <item>
      <title>EUVD-2026-264351</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-264351</link>
      <description>EUVD-2026-264351</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-264351</guid>
    </item>
    <item>
      <title>fkie_cve-2025-14927</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-14927</link>
      <description>&lt;p&gt;Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.&lt;/p&gt;
&lt;p&gt;. Was ZDI-CAN-28252.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.&lt;/p&gt;
&lt;p&gt;. Was ZDI-CAN-28252.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-14927</guid>
    </item>
    <item>
      <title>GHSA-jpvf-f2r6-62cq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jpvf-f2r6-62cq</link>
      <description>&lt;p&gt;Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.&lt;/p&gt;
&lt;p&gt;. Was ZDI-CAN-28252.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.&lt;/p&gt;
&lt;p&gt;. Was ZDI-CAN-28252.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jpvf-f2r6-62cq</guid>
    </item>
    <item>
      <title>PYSEC-2025-215</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2025-215</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: transformers&lt;/p&gt;
&lt;p&gt;Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.&lt;/p&gt;
&lt;p&gt;. Was ZDI-CAN-28252.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: transformers&lt;/p&gt;
&lt;p&gt;Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must convert a malicious checkpoint.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the convert_config function. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of the current user.&lt;/p&gt;
&lt;p&gt;. Was ZDI-CAN-28252.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2025-215</guid>
    </item>
    <item>
      <title>RHSA-2026:30078 — Red Hat Security Advisory: Red Hat AI Inference Server Model Optimization Tools 3.3.5 (CUDA)</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:30078</link>
      <description>&lt;p&gt;transformers: code execution when converting a malicious SEW model checkpoint transformers: code execution when converting a malicious SEW-D model checkpoint transformers: code execution when converting a malicious HuBERT model checkpoint transformers: code execution when processing a malicious GLM4 model file libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication OpenEXR: OpenEXR: Arbitrary code execution and information disclosure via crafted EXR file vim: arbitrary command execution via modeline sandbox bypass OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode libsndfile: integer overflow in ima_reader_init() jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers jq: jq: Denial of Service via crafted JSON object causing hash collisions urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;transformers: code execution when converting a malicious SEW model checkpoint transformers: code execution when converting a malicious SEW-D model checkpoint transformers: code execution when converting a malicious HuBERT model checkpoint transformers: code execution when processing a malicious GLM4 model file libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules poppler: Integer overflow in Poppler SplashOutputDev::tilingPatternFill leads to heap buffer overflow via unchecked dimension multiplication OpenEXR: OpenEXR: Arbitrary code execution and information disclosure via crafted EXR file vim: arbitrary command execution via modeline sandbox bypass OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode libsndfile: integer overflow in ima_reader_init() jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers jq: jq: Denial of Service via crafted JSON object causing hash collisions urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:30078</guid>
    </item>
  </channel>
</rss>
