Description
Hugging Face Transformers versions up to 4.49.0 are affected by an improper input validation vulnerability in the `image_utils.py` file. The vulnerability arises from insecure URL validation using the `startswith()` method, which can be bypassed through URL username injection. This allows attackers to craft URLs that appear to be from YouTube but resolve to malicious domains, potentially leading to phishing attacks, malware distribution, or data exfiltration. The issue is fixed in version 4.52.1.
INFO
Published Date :
2025-07-07T09:55:38.190Z
Last Modified :
2025-07-07T12:26:15.099Z
Source :
@huntr_ai
AFFECTED PRODUCTS
The following products are affected by CVE-2025-3777 vulnerability.
No data.
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-3777.