Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hugging Face Diffusers Security Flaws Threaten AI Systems

Hugging Face Diffusers Security Flaws Threaten AI Systems

Posted on August 3, 2026 By CWS

Security researchers have identified three major vulnerabilities in the Hugging Face Diffusers library, posing a significant risk to the AI supply chain. Discovered by Zafran Labs, these flaws could enable malicious actors to run arbitrary code on systems utilizing the library, bypassing the ‘trust_remote_code’ security measure meant to prevent the execution of unreviewed code.

Understanding the FaceHugger Vulnerabilities

Researchers Gal Zaban and Ido Shani from Zafran Labs have dubbed these vulnerabilities ‘FaceHugger.’ Hugging Face, often compared to a GitHub for AI, relies heavily on libraries such as Diffusers in enterprise environments, making these vulnerabilities particularly concerning. The Diffusers library, a popular Python package for state-of-the-art diffusion models, has seen over 8.1 million downloads in July 2026 alone, highlighting its widespread use.

The key feature of this library, the DiffusionPipeline API, allows models to be loaded from Hugging Face hub repositories, utilizing configuration files to set up necessary components. The ‘trust_remote_code’ parameter is crucial here, as it determines whether custom Python code from a model repository is executed during the ‘from_pretrained()’ process. However, the vulnerabilities exploit a Time-of-Check to Time-of-Use (TOCTOU) flaw in this security mechanism.

Technical Breakdown of the Vulnerabilities

The FaceHugger vulnerabilities are categorized under three major CVE identifiers. CVE-2026-44827 involves a code injection issue, allowing arbitrary code execution through custom pipelines. This occurs even when ‘trust_remote_code’ is set to False. CVE-2026-45804 presents a race condition vulnerability, introducing arbitrary code by altering configurations between HTTP calls. Lastly, CVE-2026-44513 is another code injection flaw similar to the first but triggered under slightly different conditions.

These vulnerabilities arise from the model download process, which uses two separate HTTP requests instead of a single atomic operation, allowing gaps for exploitation. The ‘trust_remote_code’ gate, only active in the initial phase, fails to prevent these exploits effectively.

Mitigation and Future Outlook

The vulnerabilities were addressed with the release of Diffusers version 0.38.0 in early May 2026. However, users employing ‘DiffusionPipeline.from_pretrained’ with custom pipelines remain at risk. Zafran Labs advises users to only utilize fully audited and trusted sources for model paths and to scrutinize local snapshots for unexpected Python files before executing them.

These incidents emphasize the necessity of regarding AI model repositories as potentially unsafe code, especially as platforms like Hugging Face become integral to enterprise operations. Adhering to these safety recommendations is crucial in preventing potential breaches through routine model downloads.

The Hacker News Tags:AI security, AI supply chain, code execution, CVE, Cybersecurity, Diffusers library, enterprise security, Hugging Face, model repositories, Python libraries, RCE, security vulnerabilities, software patch, technology news, TOCTOU

Post navigation

Previous Post: MacSync Malware Targets Mac Users with Fake Guide
Next Post: N-Able N-Central Flaw Grants Full Access to RMM Console

Related Posts

Malicious PyPI Package Posing as Solana Tool Stole Source Code in 761 Downloads Malicious PyPI Package Posing as Solana Tool Stole Source Code in 761 Downloads The Hacker News
Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation The Hacker News
Cisco Highlights Exploitation of Catalyst SD-WAN Vulnerabilities Cisco Highlights Exploitation of Catalyst SD-WAN Vulnerabilities The Hacker News
Key Insights from the 2025 State of Pentesting Report Key Insights from the 2025 State of Pentesting Report The Hacker News
BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web Shells BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web Shells The Hacker News
Apple Widens iOS 18.7.7 Update to Shield Against DarkSword Apple Widens iOS 18.7.7 Update to Shield Against DarkSword The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark