SECURITYTHE HACKER NEWS
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity security flaws in Hugging Face's Diffusers library could allow crafted model repositories to execute arbitrary code, bypassing the trust_remote_code safeguard designed to prevent unreviewed code execution. This poses a risk to the artificial intelligence (AI) supply chain.
Mentioned
Related Signal