Unauthenticated Remote Code Execution in HuggingFace Transformers via Config Injection
One Line. Zero Warnings. Full Compromise. What we found: A critical RCE vulnerability in HuggingFace transformers: CVE-2026-4372 – Config injection via _attn_implementation_internal triggers unsandboxed remote…














