A critical vulnerability tracked as CVE-2026-68770 affects Hugging Face's sentence-transformers package and allows arbitrary code execution when a model is loaded from a local path, even if applications explicitly set trust_remote_code=False. The flaw stems from a logic error in the import_module_class helper in sentence_transformers/util/misc.py, where an or os.path.exists(model_name_or_path) condition accepts existing local filesystem paths and can cause malicious Python code referenced through modules.json to run during import. The issue is classified as CWE-94 and carries a CVSS 3.1 score of 9.8, with high impact to confidentiality, integrity, and availability.
The bug affects sentence-transformers through version 5.5.1 and creates a significant AI/ML supply-chain risk for organizations that load models from disk or from directories an attacker can influence. Reporting indicates no active exploitation had been confirmed at publication, but maintainers have released a fix, with coverage pointing to version 5.6.1 as the remediated release. Organizations using local model-loading workflows are being urged to upgrade immediately and tighten controls around model directories, stored artifacts, and any process that imports untrusted model content.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The critical vulnerability CVE-2026-68770 was published, disclosing that sentence-transformers versions up to and including 5.5.1 are affected by a logic flaw in import_module_class that enables arbitrary code execution from local model paths.
VulnCheck's disclosure address received CVE-2026-68770, a sentence-transformers vulnerability involving a trust_remote_code=False bypass that can lead to arbitrary code execution during local model loading.
Coverage of the vulnerability states that the issue has been fixed in a recent sentence-transformers release, specifically version 5.6.1, and points to an associated fixing commit and pull request in the project repository.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcethreataft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.