CVE-2025-3777
CVE-2025-3777 is a low-severity vulnerability in Huggingface Transformers with a CVSS 3.x base score of 3.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-20.
Key facts
- Severity: Low (CVSS 3.x base score 3.5)
- EPSS exploit prediction: 0% (27th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-20211
- Weakness: CWE-20
- Affected product: Huggingface Transformers
- Published:
- Last modified:
Description
Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection. This allows attackers to craft URLs that appear to be from YouTube but resolve to malicious domains, potentially leading to phishing attacks, malware distribution, or data exfiltration. The issue is fixed in version 4.52.1.
Frequently asked questions
- What is CVE-2025-3777?
- Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection. This allows attackers to craft URLs that appear to be from YouTube but resolve to malicious domains, potentially leading to phishing attacks, malware distribution, or data exfiltration. The issue is fixed in version 4.52.1.
- How severe is CVE-2025-3777?
- CVE-2025-3777 has a CVSS 3.x base score of 3.5, rated low severity. It is exploitable over network with low attack complexity, requires low privileges and user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2025-3777 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (27th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-3777?
- CVE-2025-3777 affects Huggingface Transformers. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-3777?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-3777 have an EU (EUVD) identifier?
- Yes. CVE-2025-3777 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-20211.
- When was CVE-2025-3777 published?
- CVE-2025-3777 was published on 2025-07-07 and last updated on 2026-06-17.
References
- https://github.com/huggingface/transformers/commit/4dda5f71b35fb70cf602187eef84bb17a50b9082
- https://huntr.com/bounties/ccba0730-9248-4853-b7ff-5c20e6364f09
Affected products (1)
- cpe:2.3:a:huggingface:transformers:*:*:*:*:*:*:*:*
More vulnerabilities in Huggingface Transformers
- CVE-2026-5241 — Critical (CVSS 9.6): A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an…
- CVE-2024-3568 — Critical (CVSS 9.6): The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted…
- CVE-2024-11394 — High (CVSS 8.8): Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This…
- CVE-2024-11393 — High (CVSS 8.8): Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This…
- CVE-2024-11392 — High (CVSS 8.8): Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This…
- CVE-2023-6730 — High (CVSS 8.8): Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
All CVEs affecting Huggingface Transformers →
Other CWE-20 (Improper Input Validation) vulnerabilities
- CVE-2026-48056 — Critical (CVSS 10.0): Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0…
- CVE-2026-33267 — Critical (CVSS 10.0): Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0…
- CVE-2026-47668 — Critical (CVSS 10.0): DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST…
- CVE-2026-16117 — Critical (CVSS 10.0): Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix…
- CVE-2026-48316 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
- CVE-2026-48281 — Critical (CVSS 10.0): ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could…
Browse all CWE-20 (Improper Input Validation) vulnerabilities →