AOSSIE-Org / AOSSIE-Org/EduAid
🚨 Security: transformers==4.46.1 is outdated and vulnerable (multiple CVEs)
- Dominant language
- JavaScript
- Stars
- 171
- Forks
- 425
- PR merge metrics
- No merged PRs in 30d
Description
Hi team 👋,
While reviewing the dependencies in this project, I noticed that the current version of the `transformers` package (`4.46.1`) is outdated and affected by known security vulnerabilities.
### 🔐 Affected Package:
- **Package:** `transformers`
- **Current version in use:** `4.46.1`
- **Latest version:** `4.50.2`
- **Repository:** [https://github.com/huggingface/transformers](https://github.com/huggingface/transformers)
### ⚠️ Known CVEs affecting this version:
- [CVE-2024-11392](https://nvd.nist.gov/vuln/detail/CVE-2024-11392) - Deserialization of Untrusted Data Remote Code Execution Vulnerability
- [CVE-2024-11393](https://nvd.nist.gov/vuln/detail/CVE-2024-11393) - Deserialization of Untrusted Data Remote Code Execution Vulnerability
- [CVE-2024-11394](https://nvd.nist.gov/vuln/detail/CVE-2024-11394) – Deserialization of Untrusted Data Remote Code Execution Vulnerability.
- [CVE-2024-12720](https://nvd.nist.gov/vuln/detail/CVE-2024-12720) – A Regular Expression Denial of Service (ReDoS) vulnerability.
> These vulnerabilities could lead to serious security risks when using third-party or remote models in untrusted environments.
### ✅ Suggested Action:
Please consider upgrading `transformers` to the latest secure version to mitigate these issues. If helpful, I’d be happy to submit a pull request to assist with the upgrade.
Thanks for your work on this project!
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.