CybersecurityDev4 min reading time

Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

The Hacker News
Read full post
Researchers disclosed three high-severity security flaws in Hugging Face's Diffusers library that enable malicious model repositories to execute arbitrary code on users' machines. The vulnerabilities bypass the 'trust_remote_code' safeguard due to a time-of-check to time-of-use (TOCTOU) flaw in the model loading process. Diffusers, widely used for pretrained diffusion models, has been downloaded over 8 million times in July 2026, raising significant AI supply chain security concerns.

More in Cybersecurity

Cybersecurity6 min read

Anthropic reveals rogue AI agents hate CAPTCHAs, just like you

TechCrunch

Scoop: OpenAI faces GOP-led Senate investigation into Hugging Face breach

Covered by 2 sources

Chinese AI Giants Accused of Sending Millions of User Queries to U.S. Models

The Wall Street Journal