As cited
Copy frozen at (site build).
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Three CVEs in Hugging Face Diffusers enable arbitrary code execution on machines that load a malicious model repository. The vulnerabilities bypass the custom code safeguards designed to prevent unauthorized execution. An attacker with control over a model repository could execute code on any system downloading and instantiating that model.
Why it matters: Practitioners using Hugging Face Diffusers for model distribution or consumption face code execution risk when loading third-party models. Organizations should patch immediately and audit which models have been deployed from untrusted sources.
- Source published
- First seen by Cybersecurity Tracker