CVE-2025-14927 | Hugging Face transformers SEW-D convert_config code injection (ZDI-25-1148 / EUVD-2025-204823)
A vulnerability categorized as critical has been discovered in Hugging Face transformers. Impacted is an unknown function of the component SEW-D convert_config Handler. Such manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2025-14927. The attack can be launched remotely. No exploit exists.