news.mlab.sh
Back to the feed
vulnerability

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

High
Image: The Hacker News
Summary

Three high-severity vulnerabilities have been discovered in Hugging Face's Diffusers library, allowing attackers to execute arbitrary code within AI model repositories. These flaws bypass the existing security mechanism, ‘trust_remote_code,’ and could be exploited through routine model downloads, posing a significant risk to enterprise environments relying on Hugging Face’s services. A patch has been released, but temporary workarounds are available for users who cannot immediately apply it.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.