RCE in HuggingFace Transformers via malicious config.json _attn_implementation_internal
CVE-2026-4372 is a critical remote code execution vulnerability in the HuggingFace Transformers library affecting versions prior to 5.3.0, specifically reported as affecting 4.56.0 through 5.2.x when the optional kernels package is installed. The flaw is triggered during normal model loading via AutoModelForCausalLM.from_pretrained() / from_pretrained() when a malicious model repository contains a crafted config.json with the internal field _attn_implementation_internal set to an attacker-controlled HuggingFace Hub repository ID. Due to improper handling of untrusted configuration data, insufficient sanitization of internal attributes, and unsandboxed loading/execution of downloaded kernel code, Transformers can automatically download, import, and execute attacker-controlled Python code. The issue bypasses the intended trust_remote_code=False protection, making exploitation possible through the standard documented workflow without explicit user consent or visible warning.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Affected products & vendors
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical remote code execution vulnerability in the HuggingFace Transformers library caused by improper handling of untrusted model configuration data, allowing malicious config.json content to trigger arbitrary Python code execution during model loading and bypass trust_remote_code=False.
A critical remote code execution vulnerability in Hugging Face's Transformers library that allowed malicious AI models to execute arbitrary code during model loading, even with trust_remote_code=False enabled.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.