CVE-2026-2654

Source
https://cve.org/CVERecord?id=CVE-2026-2654
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2654.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-2654
Published
2026-02-18T14:16:07.277Z
Modified
2026-02-23T07:49:54.444876Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExecutor. Executing a manipulation can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

References

Affected packages

Git / github.com/huggingface/smolagents

Affected ranges

Type
GIT
Repo
https://github.com/huggingface/smolagents
Events

Affected versions

v1.*
v1.0.0
v1.24.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2654.json"