← Scan another repo

github.com/deepseek-ai/DeepSeek-V3

@ 9b4e9788e4a3

Submitted 8/4/2026, 10:25:53 AM · Status: ok

Risk grade
F
100 / 100
Findings
118
2 critical10 high94 medium12 low0 info0 on CISA KEV0ATT&CK
Showing 118 of 118 findings

Findings

  • PyTorch: `torch.load` with `weights_only=True` leads to remote code execution
    grypeCVE-2025-32434EPSS 1.9%
  • PyTorch is a Python package that provides tensor computation with stro ...
    PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.…
    trivyCVE-2025-32434
  • Deserialization of Untrusted Data in Hugging Face Transformers
    grypeCVE-2024-11392EPSS 7.1%
  • Deserialization of Untrusted Data in Hugging Face Transformers
    grypeCVE-2024-11393EPSS 2.9%
  • Deserialization of Untrusted Data in Hugging Face Transformers
    grypeCVE-2024-11394EPSS 2.4%
  • HuggingFace transformers vulnerable to remote code execution
    grypeCVE-2026-4372EPSS 0.5%
  • huggingface/transformers: Arbitrary Code Execution During Model Initialization in the LightGlue Model Loading Path
    grypeCVE-2026-5241EPSS 0.5%
  • HuggingFace transformers vulnerable to remote code execution
    A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_implementation_internal` field set to an attack…
    trivyCVE-2026-4372
  • python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting
    A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remo…
    trivyCVE-2026-5241
  • transformers: Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability
    Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit t…
    trivyCVE-2024-11393
  • transformers: Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability
    Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this v…
    trivyCVE-2024-11392
  • transformers: Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability
    Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vu…
    trivyCVE-2024-11394

This report is public.