Spaces:
Running
Running
๐ Automated Security Scan (2 findings)
#1
by Chris4K - opened
๐ Automated security scan findings
2 high-severity issue(s) (confirmed or likely) across 2 file(s).
Click to expand findings
https://huggingface.co/spaces/Chris4K/text-generation-tool#requirements.txt
- L0 [CONFIRMED] transformers 4.57.6 - GHSA-69w3-r845-3855: A vulnerability in the HuggingFace Transformers library, specifically in the
Trainerclass, allows for arbitrary code execution. The_load_rng_state()method insrc/transformers/trainer.pyat li- Fix: Upgrade transformers to 5.0.0rc3.
https://huggingface.co/spaces/Chris4K/text-generation-tool#text_generator.py (commit b43651df)
- L19 [CONFIRMED] Secret in git history: Discovered a Hugging Face Access token, which could lead to unauthorized access to AI models and sensitive data.
Scanned at 2026-04-28T11:29:59.997524Z