CVE-2025-3777
Transformers's Improper Input Validation vulnerability can be exploited through username injection
3.5
LOW
CVSS 3.1
EPSS 0.33%
描述
Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection. This allows attackers to craft URLs that appear to be from YouTube but resolve to malicious domains, potentially leading to phishing attacks, malware distribution, or data exfiltration. The issue is fixed in version 4.52.1.
如何修補 CVE-2025-3777
要修補 CVE-2025-3777,請將受影響套件升級到下列已修補版本。
- —升級至 4.52.1 或更新版本
- —升級至 4.52.1 或更新版本
CVE-2025-3777 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 4.52.1
- from 0, < 4.52.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.5 | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N |