<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:55:40 +0000</lastBuildDate>
    <item>
      <title>BREW-mlx-lm-CVE-2025-14929</title>
      <link>https://cve.radiocsirt.org/vuln/brew-mlx-lm-cve-2025-14929</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mlx-lm&lt;/p&gt;
&lt;p&gt;Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28308.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: mlx-lm&lt;/p&gt;
&lt;p&gt;Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28308.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-mlx-lm-cve-2025-14929</guid>
    </item>
    <item>
      <title>EUVD-2026-264349</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-264349</link>
      <description>EUVD-2026-264349</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-264349</guid>
    </item>
    <item>
      <title>fkie_cve-2025-14929</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-14929</link>
      <description>&lt;p&gt;Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28308.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28308.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-14929</guid>
    </item>
    <item>
      <title>GHSA-8jfx-5878-hv4v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8jfx-5878-hv4v</link>
      <description>&lt;p&gt;Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28308.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28308.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8jfx-5878-hv4v</guid>
    </item>
    <item>
      <title>PYSEC-2025-217</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2025-217</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: transformers&lt;/p&gt;
&lt;p&gt;Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28308.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: transformers&lt;/p&gt;
&lt;p&gt;Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.&lt;/p&gt;
&lt;p&gt;The specific flaw exists within the parsing of checkpoints. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28308.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2025-217</guid>
    </item>
    <item>
      <title>RHSA-2026:3713 — Red Hat Security Advisory: RHOAI 3.3 - Red Hat OpenShift AI</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:3713</link>
      <description>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation vllm: Server Side request forgery (SSRF) in MediaConnector keras: Path Traversal Vulnerability in keras node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications php: PHP: Denial of Service via invalid character sequence in PDO PostgreSQL prepared statement transformers: code execution when processing a malicious Perceiver model file transformers: code execution when processing a malicious Transformer-XL model file diffusers: Hugging Face Diffusers: Remote Code Execution via Deserialization of Untrusted Data transformers: code execution when processing a malicious megatron_gpt2 model file accelerate: Hugging Face Accelerate: Remote Code Execution via Deserialization of Untrusted Data transformers: code execution when converting a malicious SEW model checkpoint transformers: code execution when converting a malicious SEW-D model checkpoint transformers: code execution when converting a malicious HuBERT model checkpoint transformers: code execution when processing a malicious X-CLIP model file transformers: code execution when processing a malicious GLM4 model file qs: qs: Denial of Service via improper input validation in array parsing vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects v…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation vllm: Server Side request forgery (SSRF) in MediaConnector keras: Path Traversal Vulnerability in keras node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications php: PHP: Denial of Service via invalid character sequence in PDO PostgreSQL prepared statement transformers: code execution when processing a malicious Perceiver model file transformers: code execution when processing a malicious Transformer-XL model file diffusers: Hugging Face Diffusers: Remote Code Execution via Deserialization of Untrusted Data transformers: code execution when processing a malicious megatron_gpt2 model file accelerate: Hugging Face Accelerate: Remote Code Execution via Deserialization of Untrusted Data transformers: code execution when converting a malicious SEW model checkpoint transformers: code execution when converting a malicious SEW-D model checkpoint transformers: code execution when converting a malicious HuBERT model checkpoint transformers: code execution when processing a malicious X-CLIP model file transformers: code execution when processing a malicious GLM4 model file qs: qs: Denial of Service via improper input validation in array parsing vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects v…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:3713</guid>
    </item>
  </channel>
</rss>
