{"id":2172,"date":"2026-08-03T08:25:44","date_gmt":"2026-08-03T08:25:44","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2172"},"modified":"2026-08-03T08:25:44","modified_gmt":"2026-08-03T08:25:44","slug":"hugging-face-diffusers-flaws-could-let-model-repositories-execute-arbitrary-code","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2172","title":{"rendered":"Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 03, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ AI Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiWQmUt2QHxTfiXiolir9akmVh8dT5di3UBDtD7H2IJlkWQ4x4VmeTUEZo8CUvz2q2FXCvxTJDHenWPzqPeSbnlCYSRTNGULKdWRJnsmVg7SVJT_BBPABxqRuvr22Z9V2C6P51fRjSGzgAlHMzEn-MjA4yTMfCaM91ujVajF8GJqYg9ZaZELXsCc-GMnYq8\/s1700-e365\/hugging.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Three high-severity security flaws have been disclosed in Hugging Face&#8217;s <a href=\"https:\/\/pypi.org\/project\/diffusers\/#description\" target=\"_blank\">Diffusers<\/a> library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk.<\/p>\n<p>\u00abThese vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the custom pipelines loading process,\u00bb Zafran Labs researchers Gal Zaban and Ido Shani <a href=\"https:\/\/www.zafran.io\/resources\/facehugger-vulnerabilities-in-hugging-face-diffusers-open-door-to-supply-chain-attacks-on-enterprise-ai\" target=\"_blank\">said<\/a> in an analysis published last week.<\/p>\n<p>The shortcomings have been collectively named <strong>FaceHugger<\/strong>.<\/p>\n<p>With Hugging Face becoming the \u00abGitHub of the AI era\u00bb and its libraries and repositories prevalent in enterprise environments, vulnerabilities in libraries like Diffusers can grant attackers extensive access owing to how the library is embedded into production pipelines, CI\/CD systems, and container images.<\/p>\n<p>Diffusers is a <a href=\"https:\/\/huggingface.co\/docs\/diffusers\/en\/index\" target=\"_blank\">Python package<\/a> that serves as a library of state-of-the-art (SOTA) pretrained diffusion models for generating videos, images, and audio. According to statistics shared on pepy.tech, the package has been <a href=\"https:\/\/pepy.tech\/projects\/diffusers?timeRange=threeMonths&amp;category=version&amp;includeCIDownloads=true&amp;granularity=monthly&amp;viewType=line&amp;versions=Total%2C0.*\" target=\"_blank\">downloaded<\/a> more than 8.1 million times in July 2026.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>One of the key capabilities of the library is to locally load a model from a Hugging Face hub repository via the <a href=\"https:\/\/huggingface.co\/docs\/diffusers\/v0.39.0\/en\/api\/pipelines\/overview#diffusers.DiffusionPipeline\" target=\"_blank\">DiffusionPipeline<\/a> API, which, in turn, makes use of a configuration file to initialize specific pipeline and component classes, along with custom pipeline code.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The \u00abtrust_remote_code\u00bb parameter in Diffusers is a security safeguard that controls whether custom Python code hosted inside a model repository is allowed to execute during \u00abfrom_pretrained()\u00bb loading. Setting it to \u00abTrue\u00bb permits custom code execution, while \u00abFalse\u00bb or omitting it blocks unverified code from running.<\/p>\n<p>\u00abThe root cause of all different RCE variants [&#8230;] is that the trust check lives entirely in the first phase,\u00bb Zafran explained. \u00abTherefore, any method that makes the loader see custom code that the gate did not, allows bypassing the trust_remote_code mechanism.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhvM63veS-QQ4F95eiHeX_Vy-uoJ3R1_9WD1T6F3xiNh4knGqz1Jfpg3YP15O80DXp2-ohajtnpf-a4QbQmHrYsD8dAKlyRJtHufUdXesf1ndiQZuCCAXmoEJsddWA2jhd_pn38oqvZXLfDiGOgR5nO1h2ERCYe8S4TLDceUu6SD2b_E4VakXX7I_U09xyg\/s1700-e365\/poc.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhvM63veS-QQ4F95eiHeX_Vy-uoJ3R1_9WD1T6F3xiNh4knGqz1Jfpg3YP15O80DXp2-ohajtnpf-a4QbQmHrYsD8dAKlyRJtHufUdXesf1ndiQZuCCAXmoEJsddWA2jhd_pn38oqvZXLfDiGOgR5nO1h2ERCYe8S4TLDceUu6SD2b_E4VakXX7I_U09xyg\/s1700-e365\/poc.jpg\" alt=\"\" border=\"0\" data-original-height=\"1007\" data-original-width=\"1641\"\/><\/a><\/div>\n<p>Each variant has been traced back to a case of Time-of-Check to Time-of-Use (TOCTOU), with the model download designed as two sequential, non-atomic HTTP requests instead of one a \u00absingle atomic operation\u00bb and the \u00abtrust_remote_code\u00bb security gate configured to run only against the first.<\/p>\n<p>The vulnerabilities are listed below &#8211;<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/github.com\/advisories\/GHSA-j7w6-vpvq-j3gm\" target=\"_blank\">CVE-2026-44827<\/a><\/strong> (CVSS score: 8.8) &#8211; A code injection vulnerability that allows arbitrary code to be loaded through the custom_pipeline flow from a Hub repository by means of a crafted pipeline with the name \u00abNone.py\u00bb despite passing trust_remote_code=False (or omitting it, which is the default).<\/li>\n<li><strong><a href=\"https:\/\/github.com\/advisories\/GHSA-7wx4-6vff-v64p\" target=\"_blank\">CVE-2026-45804<\/a><\/strong> (CVSS score: 7.5) &#8211; A race condition vulnerability that allows arbitrary code to be introduced to a repository by modifying the configuration between the hf_hub_download and snapshot_download HTTP calls to the Hub, leading to code execution.<\/li>\n<li><strong><a href=\"https:\/\/github.com\/advisories\/GHSA-98h9-4798-4q5v\" target=\"_blank\">CVE-2026-44513<\/a><\/strong> (CVSS score: 8.8) &#8211; A code injection vulnerability that allows arbitrary code to be loaded through the custom_pipeline flow from a Hub repository despite passing trust_remote_code=False (or omitting it).<\/li>\n<\/ul>\n<p>Following responsible disclosure, the vulnerabilities were addressed in Diffusers version 0.38.0, released in early May 2026. Any user who invokes \u00abDiffusionPipeline.from_pretrained\u00bb with custom pipelines is impacted.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThe underlying problem is that artifacts pulled from AI repositories are frequently treated as passive data, when configuration files, loaders, and custom pipeline code can quietly cross into executable code and turn a routine model load into an initial-access vector,\u00bb the researchers added.<\/p>\n<p>If immediate patching is not an option, the project maintainers have recommended the following workarounds &#8211;<\/p>\n<ul>\n<li>Only call from_pretrained with pretrained_model_name_or_path, custom_pipeline, and local snapshot directories from fully trusted sources that have been audited.<\/li>\n<li>Do not pass custom_pipeline= pointing at a Hub repository different from the primary pretrained_model_name_or_path before reading its pipeline.py.<\/li>\n<li>Before calling from_pretrained on a local snapshot, inspect the snapshot for unexpected *.py files, especially under component subdirectories (unet\/, scheduler\/, etc.) and at the snapshot root.<\/li>\n<\/ul>\n<p>\u00abThese vulnerabilities underscore the critical need to treat AI model repositories as untrusted code, particularly as enterprise reliance on platforms like Hugging Face continues to grow,\u00bb Zafran said. \u00abA routine model download can easily become a vector for arbitrary code execution if security boundaries like trust_remote_code are bypassed.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 03, 2026Vulnerability \/ AI Security Three high-severity security flaws have been disclosed in Hugging Face&#8217;s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2173,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1222,10,2850,1832,1443,11,1442,111,1738],"class_list":["post-2172","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-arbitrary","tag-code","tag-diffusers","tag-execute","tag-face","tag-flaws","tag-hugging","tag-model","tag-repositories"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2172","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2172"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2172\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2173"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2172"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2172"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2172"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}