🧬 Known OSS vulnerabilities — OSV-Scannerⓘ4 found · 1 serious
Your dependencies cross-checked against the OSV vulnerability database.
SeriousPYSEC-2026-2290 A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The
A package you depend on has a known security hole (CVE-2026-5241). Fix: Update that package to its patched version.
Worth fixingPYSEC-2025-217 Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af
A package you depend on has a known security hole (CVE-2025-14929). Fix: Update that package to its patched version.
Worth fixingPYSEC-2026-2288 A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at li
A package you depend on has a known security hole (CVE-2026-1839). Fix: Update that package to its patched version.
Worth fixingPYSEC-2026-2289 A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.
About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.