transformers is vulnerable to Command Injection
60
Medium Risk
Affected versions of the transformers library are vulnerable to command injection due to the use of subprocess.Popen with the shell=True parameter. This vulnerability could potentially allow attackers to execute arbitrary code.
You are affected if you are using a version that falls within the vulnerable range.
transformers is vulnerable to Command Injection in versions 4.26.0 - 4.36.2.
Upgrade the transformers library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant