Hugging Face

Security Scorecard

Score

90B

Total CVEs

6

Patch Rate

83%

5 patched

Avg Response

-

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical0
High5
Medium1
Low0

Patch Status

Patched5 (83%)
Partial/Workaround0 (0%)
Unpatched1 (17%)

CVEs (11)

CVE IDTitleSeverityScoreDaysPatch
CVE-2025-14929X-CLIP Checkpoint Conversion VulnerabilityHigh7.829dUnpatched
CVE-2025-14928HuBERT Code Injection VulnerabilityHigh7.8-Patched
CVE-2025-14920Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution VulnerabilityHigh7.8-Patched
CVE-2025-14921Transformer-XL Model Deserialization VulnerabilityHigh7.8-Patched
CVE-2025-14930Hugging Face Transformers GLM4 Remote Code Execution VulnerabilityHigh7.8-Patched
CVE-2025-11844-Medium5.4-Patched
CVE-2025-14924-N/A-0dUnpatched
CVE-2025-14925-N/A-0dUnpatched
CVE-2025-14926-N/A-0dUnpatched
CVE-2025-14927-N/A-0dUnpatched