AOSSIE-Org / AOSSIE-Org/EduAid
🚨 Security: transformers==4.46.1 is outdated and vulnerable (multiple CVEs)
- Lenguaje dominante
- JavaScript
- Estrellas
- 171
- Forks
- 425
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Descripción
Hi team 👋,
While reviewing the dependencies in this project, I noticed that the current version of the `transformers` package (`4.46.1`) is outdated and affected by known security vulnerabilities.
### 🔐 Affected Package:
- **Package:** `transformers`
- **Current version in use:** `4.46.1`
- **Latest version:** `4.50.2`
- **Repository:** [https://github.com/huggingface/transformers](https://github.com/huggingface/transformers)
### ⚠️ Known CVEs affecting this version:
- [CVE-2024-11392](https://nvd.nist.gov/vuln/detail/CVE-2024-11392) - Deserialization of Untrusted Data Remote Code Execution Vulnerability
- [CVE-2024-11393](https://nvd.nist.gov/vuln/detail/CVE-2024-11393) - Deserialization of Untrusted Data Remote Code Execution Vulnerability
- [CVE-2024-11394](https://nvd.nist.gov/vuln/detail/CVE-2024-11394) – Deserialization of Untrusted Data Remote Code Execution Vulnerability.
- [CVE-2024-12720](https://nvd.nist.gov/vuln/detail/CVE-2024-12720) – A Regular Expression Denial of Service (ReDoS) vulnerability.
> These vulnerabilities could lead to serious security risks when using third-party or remote models in untrusted environments.
### ✅ Suggested Action:
Please consider upgrading `transformers` to the latest secure version to mitigate these issues. If helpful, I’d be happy to submit a pull request to assist with the upgrade.
Thanks for your work on this project!
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Evaluación
Este issue todavía no se ha evaluado.