PatchSiren

Hugging Face CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Hugging Face CVE published 2026-08-20

CVE-2026-15679

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T17:17:21.050Z and has not been modified since then. This vulnerability, identified as CVE-2026-15679, affects Hugging Face PyTorch Image Models, allowing remote attackers to execute arbitrary code. The vulnerability exists within the parsing of checkpoints in Hugging Face PyTorch Image Models, re [truncated]

CRITICAL Hugging Face CVE published 2026-07-31

CVE-2026-68770

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T21:17:32.440Z and has not been modified since then. The sentence-transformers library contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py. [truncated]

CRITICAL Hugging Face CVE published 2026-04-23

CVE-2026-25874

LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels without TLS in the policy server and robot client components. This vulnerability allows an unauthenticated network-reachable attacker to achieve arbitrary code execution on the server or client by sending a craft [truncated]