Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-4372 HuggingFace transformers vulnerable to remote code executionCVE-2026-5241 python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code settingCVE-2025-3933 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformersCVE-2025-5197 transformers: Transformers ReDoS VulnerabilityCVE-2025-6051 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformersCVE-2025-6638 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformersCVE-2025-6921 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformersCVE-2026-1839 transformers: HuggingFace Transformers: Arbitrary code execution via malicious checkpoint fileCVE-2025-3777 transformers: Improper Input Validation in huggingface/transformersYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2026-2290 A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The PYSEC-2026-2102 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in respPYSEC-2026-457 Arbitrary Code Execution in PillowPYSEC-2023-238 Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or ParquePYSEC-2026-2477 flash-attention contains an insecure deserialization vulnerability in its checkpoint loading mechanismPYSEC-2026-2178 Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across PYSEC-2026-2179 Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplyiPYSEC-2026-2663 ModelScope is vulnerable to arbitrary code injection via a crafted modulePYSEC-2025-211 Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instalPYSEC-2025-212 Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected iPYSEC-2025-213 Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installaPYSEC-2025-214 Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of HuggiPYSEC-2025-215 Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of HugPYSEC-2025-216 Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of HuPYSEC-2025-217 Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on afPYSEC-2025-218 Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PYSEC-2026-1977 Transformers is vulnerable to ReDoS attack through its DonutProcessor classPYSEC-2026-1980 Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizerPYSEC-2026-1981 Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizerPYSEC-2026-1983 Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerabilityPYSEC-2026-1988 Hugging Face Transformers library has Regular Expression Denial of ServicePYSEC-2026-2288 A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at liPYSEC-2026-2289 A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.PYSEC-2026-1100 AIOHTTP vulnerable to denial of service through large payloadsPYSEC-2026-1101 AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bombCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.