Hugging Face Transformers: RCE Vulnerability in Model Configurations Bypasses Security Measures4. June 2026AI Models, Claude Code, CybersecurityHugging Face Transformers allows silent remote code execution via obfuscated parameters in model configurations as long as the optional kernels package is installed (CVE-2026-4372, patched in 5.3.0). Share on: