
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14921 is a deserialization of untrusted data vulnerability in Hugging Face Transformers, specifically affecting the Transformer-XL model file parsing component. It allows remote attackers to execute arbitrary code on affected installations when a user opens a malicious model file or visits a malicious page. The vulnerability was reported to the vendor on November 4, 2024, rejected by Hugging Face on December 17, 2024, and publicly disclosed as a 0-day advisory by Zero Day Initiative (ZDI) on December 18, 2025. The affected version identified in CPE records is Hugging Face Transformers 4.54.1, and IBM Storage Fusion products bundling this library are also affected. It carries a CVSS v3.0 score of 7.8 (High), assigned by ZDI (ZDI Advisory, Red Hat Bugzilla).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) and is associated with CAPEC-586 (Object Injection). The flaw exists within the parsing logic for Transformer-XL model files, where user-supplied data is not properly validated before being deserialized, allowing an attacker to embed malicious payloads within a crafted model file. Exploitation requires local access in the sense that the attacker must deliver a malicious file to the target (e.g., via a malicious download link or page), after which the victim must open the file — triggering deserialization and arbitrary code execution in the context of the current user. The vulnerability was tracked internally by ZDI as ZDI-CAN-25424 (ZDI Advisory, Red Hat Bugzilla).
Successful exploitation results in arbitrary code execution in the context of the current user, with high impact to confidentiality, integrity, and availability. An attacker could execute malicious code, exfiltrate sensitive data (including model weights, training data, or credentials accessible to the user), modify system files, or disrupt operations. In environments where Hugging Face Transformers is deployed in ML pipelines or shared infrastructure (e.g., IBM Fusion HCI), exploitation could facilitate lateral movement or broader compromise of the hosting environment (ZDI Advisory, IBM Advisory).
A proof-of-concept exploit reference is available via the ZDI advisory (ZDI-25-1149), published as a 0-day on December 18, 2025, after Hugging Face rejected the vulnerability report. There is no current evidence of in-the-wild exploitation. The EPSS score is approximately 0.0022 (0.22%), indicating a low but non-zero probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. User interaction is required, which somewhat limits opportunistic exploitation (ZDI Advisory).
.pkl or similar serialized format) containing a malicious deserialization payload that executes arbitrary OS commands upon loading.from_pretrained() or a similar model loading API that processes Transformer-XL files)..pkl, .bin, or other serialized formats) in model cache directories (e.g., ~/.cache/huggingface/); presence of web shells or scripts in application directories created around the time of model loading.bash, sh, curl, wget, nc, python -c); unexpected network connections initiated by the Python process.ZDI states that given the nature of the vulnerability, the only salient mitigation is to restrict interaction with the product — specifically, avoid loading Transformer-XL model files from untrusted sources. A patch was noted as available via Red Hat CVE advisory as of December 24, 2025, and IBM has released an advisory for affected IBM Fusion and IBM Fusion HCI products. Users should update Hugging Face Transformers to a patched version, apply IBM's fix per their advisory, restrict model loading to verified and trusted sources, and apply least-privilege principles to accounts running ML workloads (ZDI Advisory, Red Hat Bugzilla, IBM Advisory).
The vulnerability was disclosed as a 0-day by ZDI after Hugging Face rejected the original vulnerability report submitted through a third-party bug bounty program in November 2024. ZDI notified the vendor of its intent to publish in December 2025, and proceeded with public disclosure after no patch was provided. The case highlights ongoing concerns about the security of ML model file formats — particularly pickle-based serialization — which have been a known risk in the AI/ML community for years. No significant social media campaigns or named threat actor attributions have been observed in connection with this CVE (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."