Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://huntr.com/bounties/e1a3e548-e53a-48df-b708-9ee62140963c | patch third party advisory exploit |
https://github.com/huggingface/transformers/commit/1d63b0ec361e7a38f1339385e8a5a855085532ce | patch |