vulnerability
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
High
Summary
Three high-severity vulnerabilities have been discovered in Hugging Face's Diffusers library, allowing attackers to execute arbitrary code within AI model repositories. These flaws bypass the existing security mechanism, ‘trust_remote_code,’ and could be exploited through routine model downloads, posing a significant risk to enterprise environments relying on Hugging Face’s services. A patch has been released, but temporary workarounds are available for users who cannot immediately apply it.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
