CVE-2026-5241 | huggingface transformers up to 5.4.x Python AutoModel.from_pretrained trust_remote_code inclusion of functionality from untrusted control sphere
A vulnerability identified as problematic has been detected in huggingface transformers up to 5.4.x. Affected is the function AutoModel.from_pretrained of the component Python Module. This manipulation of the argument trust_remote_code causes inclusion of functionality from untrusted control sphere.
This vulnerability is registered as CVE-2026-5241. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.