CVE-2023-6730

CRITICAL9.0EPSS 0.16%

transformers has a Deserialization of Untrusted Data vulnerability

Published: 12/19/2023Modified: 11/22/2024
Also known as:GHSA-3863-2447-669pPYSEC-2023-300

Description

Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.0.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.0CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

References (5)