CVE-2026-71281 | Hugging Face peft up to 0.19.1 Initialization Modules corda.py torch.load deserialization
A vulnerability classified as problematic has been found in Hugging Face peft up to 0.19.1. The impacted element is the function torch.load of the file src/peft/tuners/lora/corda.py of the component Initialization Modules. Performing a manipulation results in deserialization.
This vulnerability is reported as CVE-2026-71281. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More