LIVE NEWS
  • Fauci invokes 5th Amendment right during GOP-led hearing on COVID origins
  • $47 million program offers hybrid university-industry Ph.D. training
  • Meta’s revenue beat, but free cash flow fell 91%
  • Nicaragua’s Daniel Ortega aims to bar ‘traitors’ from future elections | Politics News
  • OpenAI report links coding agents to faster science software builds
  • World falling short on 22 of 23 nature targets for 2030, says draft UN report
  • Divided Fed holds interest rates steady : NPR
  • Up to six designs could move ahead in Air Force’s next robot-wingman effort
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Cybersecurity

Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard

primereportsBy primereportsJuly 28, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Share
Facebook Twitter LinkedIn Pinterest Email


Three high-severity flaws in vulnerable versions of Hugging Face’s diffusers library let crafted model repositories silently execute arbitrary code during affected loading flows, bypassing the safeguard built to prevent exactly that.

According to research from threat exposure management firm Zafran Security published on July 27, the flaws defeated trust_remote_code, the check meant to stop unreviewed code running when a model is fetched.

The library draws roughly seven million downloads a month, close to 200,000 a day, sitting inside production AI pipelines, CI/CD systems and container images.

The findings land days after OpenAI’s frontier models breached Hugging Face’s production infrastructure, logging over 17,000 events across a weekend. That intrusion exploited dataset-processing paths; these target model loading. Zafran said both point to the same weakness: AI repository content is treated as passive data when it can quietly cross into executable code.

Commenting on the OpenAI incident, Crystal Morin, cybersecurity strategist at AI cloud security firm Sysdig, said what caught the Hugging Face intrusion was “behavioral anomaly detection at the infrastructure level,” not perimeter defenses. Teams should verify they can spot a privileged container spinning up from an application process, she said, and back up model weights as rigorously as databases.

Read more on Hugging Face threats: Malicious Hugging Face Repository Typosquats OpenAI

Check Separated from Code Load

All three flaws shared a root cause: the trust check runs at a different point from the actual code load. When a model is fetched, the check ran against the configuration file in the first of two sequential, non-atomic HTTP requests, so anything that makes the loader see custom code the check did not created a bypass.

CVE-2026-44827 (CVSS 8.8) exploited a string-formatting quirk. With no custom pipeline argument supplied, the loader built the filename None.py and checked whether it existed in the repository. The check used a different code path and did not flag None.py, so a repository containing that file passes while executing attacker code on load.

CVE-2026-45804 (CVSS 7.5) exploited the gap between the two requests. Modifying the configuration to reference custom code after the first request completed but before the second ran executes the injected code. Zafran’s testing put the window at around 0.3 seconds, and the exploit required an uncached first download. Still, the firm noted a popular repository could achieve statistical success by briefly pushing a malicious config and reverting it.

Patched in May

Three further variants under CVE-2026-44513 (CVSS 8.8) shared the root cause, including one bypassing the check entirely when loading from a local snapshot. Zafran also disclosed a parallel flaw in Hugging Face’s transformers package, which it said the security team has acknowledged.

Jeremy Powell, CISO at log management vendor Sumo Logic, said the defenses that mattered now were “the unglamorous ones”: egress control, segmentation and credential hygiene, alongside detection operating at the speed of the attack.

Hugging Face released diffusers 0.38.0 on May 1, moving the security checks to the dynamic-module loading step and closing the identified variants. Zafran said it reported the first two flaws on March 19, and CVEs were published in May.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleIs the Bitcoin bottom in? Key levels to watch after summer drop By Investing.com
Next Article SpaceX, Blue Origin may get quicker launch OK with fewer environmental rules
primereports
  • Website

Related Posts

Cybersecurity

US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

July 29, 2026
Cybersecurity

Tengu botnet reboots Linux devices to survive removal

July 29, 2026
Cybersecurity

OpenAI’s rogue agent shows why we need federal rules for autonomous AI

July 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Cybersecurity
  • Crypto
  • Artificial Intelligence
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Fauci invokes 5th Amendment right during GOP-led hearing on COVID origins
  • $47 million program offers hybrid university-industry Ph.D. training
  • Meta’s revenue beat, but free cash flow fell 91%
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.