A critical vulnerability in Hugging Face's Transformers library, tracked as CVE-2026-4372, has been disclosed by Pluto Security Inc., allowing attacker-controlled AI models to execute arbitrary code on victim machines through standard model-loading commands, regardless of security measures advised by Hugging Face.