CVE-2026-71281: Huggingface Peft
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py line ~101) call torch.load on config-specified cache/covariance files without weights_only=True, bypassing peft's own safe-loading wrapper used elsewhere in the codebase.
Affected products
- Huggingface Peft: up to and including 0.19.1
Published 2026-08-05. Last modified 2026-08-26.