Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-3863-2447-669p: transformers has a Deserialization of Untrusted Data vulnerability

Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.0.

ghsa
#vulnerability#git

transformers has a Deserialization of Untrusted Data vulnerability

Critical severity GitHub Reviewed Published Dec 19, 2023 to the GitHub Advisory Database • Updated Dec 28, 2023

ghsa: Latest News

GHSA-36rr-ww3j-vrjv: The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.