Skip to content

Patch release to support transformers >= 5.0.0 #2432

Description

@hteeyeoh

System Info

- transformers: 5.0.0
- optimum: 2.1.0
- optimum-intel: 1.27.0
- Python: x.y
- Platform: (CPU/OpenVINO)

Who can help?

No response

Information

  • The official example scripts
  • My own modified scripts

Tasks

  • An officially supported task in the examples folder (such as GLUE/SQuAD, ...)
  • My own task or dataset (give details below)

Reproduction (minimal, reproducible, runnable)

install optimum, optimum-intel with transformers version 5.x

Expected behavior

Need patch/support to support transformers with version 5.x to overcome the following CVE reported:

A vulnerability in the HuggingFace Transformers library, specifically in the Trainer class, allows for arbitrary code execution. The _load_rng_state() method in src/transformers/trainer.py at line 3059 calls torch.load() without the weights_only=True parameter. This issue affects all versions of the library supporting torch>=2.2 when used with PyTorch versions below 2.6, as the safe_globals() context manager provides no protection in these versions. An attacker can exploit this vulnerability by supplying a malicious checkpoint file, such as rng_state.pth, which can execute arbitrary code when loaded. The issue is resolved in version v5.0.0rc3.

optimum[nncf,openvino] → optimum-intel[openvino] → transformers <4.58

This is expected given current constraints, but users upgrading to
Transformers 5.x are blocked from using Optimum OpenVINO/NNCF
features.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions