GLiNER2 is now the project's default extraction backend. `gliner2[local]` hard-pins `transformers<5`, which can't coexist in the workspace lock with the `transformers>=5.0.0rc3` floor that fixed CVE-2026-1839 (GHSA-69w3-r845-3855, an RCE in `Trainer`'s checkpoint loading). The floor was dropped so that gliner2 could become a declared dependency. This was a deliberate, temporary trade-off; security is being handled separately.
Exposure
The vulnerable path is `transformers.Trainer` checkpoint loading. The project uses transformers for inference only (GLiNER2 extraction, embeddings) and never trains or loads Trainer checkpoints. That is a statement about our own code, not a mitigation for anyone who imports transformers alongside it.
To resolve
One of:
- gliner2 releases with `transformers>=5` support;
- a patched 4.x transformers line with the fix backported, used as the floor;
- vendoring or forking gliner2's inference path without the pin.
Then restore the floor in the root `pyproject.toml`.
GLiNER2 is now the project's default extraction backend. `gliner2[local]` hard-pins `transformers<5`, which can't coexist in the workspace lock with the `transformers>=5.0.0rc3` floor that fixed CVE-2026-1839 (GHSA-69w3-r845-3855, an RCE in `Trainer`'s checkpoint loading). The floor was dropped so that gliner2 could become a declared dependency. This was a deliberate, temporary trade-off; security is being handled separately.
Exposure
The vulnerable path is `transformers.Trainer` checkpoint loading. The project uses transformers for inference only (GLiNER2 extraction, embeddings) and never trains or loads Trainer checkpoints. That is a statement about our own code, not a mitigation for anyone who imports transformers alongside it.
To resolve
One of:
Then restore the floor in the root `pyproject.toml`.