Dossier
artificial intelligence (AI) supply chain
Coverage of artificial intelligence (AI) supply chain in the Nexus archive.
- Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity security flaws in Hugging Face's Diffusers library could allow crafted model repositories to execute arbitrary code, bypassing the trust_remote_code safeguard designed to prevent unreviewed code execution. This poses a risk to the artificial intelligence (AI) supply chain.
- Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
Cybersecurity researchers identified a critical design flaw in the Model Context Protocol (MCP) that could enable remote code execution (RCE), posing significant risks to systems using vulnerable MCP implementations and threatening the AI supply chain.