Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hugging Face Diffusers Security Flaws Threaten AI Systems

Hugging Face Diffusers Security Flaws Threaten AI Systems

Posted on August 3, 2026 By CWS

Security researchers have identified three major vulnerabilities in the Hugging Face Diffusers library, posing a significant risk to the AI supply chain. Discovered by Zafran Labs, these flaws could enable malicious actors to run arbitrary code on systems utilizing the library, bypassing the ‘trust_remote_code’ security measure meant to prevent the execution of unreviewed code.

Understanding the FaceHugger Vulnerabilities

Researchers Gal Zaban and Ido Shani from Zafran Labs have dubbed these vulnerabilities ‘FaceHugger.’ Hugging Face, often compared to a GitHub for AI, relies heavily on libraries such as Diffusers in enterprise environments, making these vulnerabilities particularly concerning. The Diffusers library, a popular Python package for state-of-the-art diffusion models, has seen over 8.1 million downloads in July 2026 alone, highlighting its widespread use.

The key feature of this library, the DiffusionPipeline API, allows models to be loaded from Hugging Face hub repositories, utilizing configuration files to set up necessary components. The ‘trust_remote_code’ parameter is crucial here, as it determines whether custom Python code from a model repository is executed during the ‘from_pretrained()’ process. However, the vulnerabilities exploit a Time-of-Check to Time-of-Use (TOCTOU) flaw in this security mechanism.

Technical Breakdown of the Vulnerabilities

The FaceHugger vulnerabilities are categorized under three major CVE identifiers. CVE-2026-44827 involves a code injection issue, allowing arbitrary code execution through custom pipelines. This occurs even when ‘trust_remote_code’ is set to False. CVE-2026-45804 presents a race condition vulnerability, introducing arbitrary code by altering configurations between HTTP calls. Lastly, CVE-2026-44513 is another code injection flaw similar to the first but triggered under slightly different conditions.

These vulnerabilities arise from the model download process, which uses two separate HTTP requests instead of a single atomic operation, allowing gaps for exploitation. The ‘trust_remote_code’ gate, only active in the initial phase, fails to prevent these exploits effectively.

Mitigation and Future Outlook

The vulnerabilities were addressed with the release of Diffusers version 0.38.0 in early May 2026. However, users employing ‘DiffusionPipeline.from_pretrained’ with custom pipelines remain at risk. Zafran Labs advises users to only utilize fully audited and trusted sources for model paths and to scrutinize local snapshots for unexpected Python files before executing them.

These incidents emphasize the necessity of regarding AI model repositories as potentially unsafe code, especially as platforms like Hugging Face become integral to enterprise operations. Adhering to these safety recommendations is crucial in preventing potential breaches through routine model downloads.

The Hacker News Tags:AI security, AI supply chain, code execution, CVE, Cybersecurity, Diffusers library, enterprise security, Hugging Face, model repositories, Python libraries, RCE, security vulnerabilities, software patch, technology news, TOCTOU

Post navigation

Previous Post: MacSync Malware Targets Mac Users with Fake Guide
Next Post: N-Able N-Central Flaw Grants Full Access to RMM Console

Related Posts

Emerging Cyber Threats: OAuth Abuse and Beyond Emerging Cyber Threats: OAuth Abuse and Beyond The Hacker News
Why More Security Leaders Are Selecting AEV Why More Security Leaders Are Selecting AEV The Hacker News
Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry The Hacker News
Cybercriminals Deploy CORNFLAKE.V3 Backdoor via ClickFix Tactic and Fake CAPTCHA Pages Cybercriminals Deploy CORNFLAKE.V3 Backdoor via ClickFix Tactic and Fake CAPTCHA Pages The Hacker News
Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms The Hacker News
FreePBX Servers Targeted by Zero-Day Flaw, Emergency Patch Now Available FreePBX Servers Targeted by Zero-Day Flaw, Emergency Patch Now Available The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark