Dossier
trust_remote_code
Coverage of trust_remote_code in the Nexus archive.
- Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity security flaws in Hugging Face's Diffusers library could allow crafted model repositories to execute arbitrary code, bypassing the trust_remote_code safeguard designed to prevent unreviewed code execution. This poses a risk to the artificial intelligence (AI) supply chain.