Topic

#cve-2026-1839

1 article exploring cve-2026-1839. Expert insights and analysis from our editorial team.

Showing 1–1 of 1 articles

Articles

Newest first
Security

CVE-2026-1839: Transformers Trainer's safe_globals Is a No-Op on PyTorch < 2.6, Exposing [Checkpoint RCE](/articles/picklescan-1-0-4-patches-a-cvss-10-0-pkgutil-resolve-name-bypass-and-six/)

CVE-2026-1839 hits Transformers Trainer: [torch.load() on rng_state.pt](/articles/hugging-face-lerobot-cve-2026-25874-unauthenticated-pickle-loads-rce-in-grpc/)h runs pickle; safe_globals is a no-op on PyTorch < 2.6, so upgrading Transformers alone is insufficient.