PT-2025-28155 · Hugging Face · Huggingface/Transformers

Published

2025-03-19

·

Updated

2025-08-07

·

CVE-2025-3777

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Hugging Face Transformers versions prior to 4.52.1
Description: Hugging Face Transformers is affected by an improper input validation vulnerability in the image utils.py file. The vulnerability stems from insecure URL validation using the startswith() method, which can be bypassed through URL username injection. This allows attackers to craft URLs that appear to be from YouTube but resolve to malicious domains, potentially leading to phishing attacks, malware distribution, or data exfiltration.
Recommendations: Update to Hugging Face Transformers version 4.52.1 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12551
CVE-2025-3777
GHSA-PHHR-52QP-3MJ4

Affected Products

Huggingface/Transformers