BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

FaceHugger flaws in Hugging Face Diffusers allow AI supply chain attacks

Three FaceHugger flaws in Hugging Face Diffusers allow code execution, bypassing safeguards.

  • Three high-severity vulnerabilities, collectively named FaceHugger, were disclosed in Hugging Face’s Diffusers library, allowing arbitrary code execution on machines that load crafted model repositories.
  • The flaws bypass the trust_remote_code safeguard, which is designed to prevent unreviewed code from running during custom pipeline loading.
  • Attackers can exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition due to the model download being split into two non-atomic HTTP requests.
  • The vulnerabilities were patched in Diffusers version 0.38.0 (released May 2026), and users are advised to only load models from trusted, audited sources.

Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library, enabling crafted model repositories to stealthily execute arbitrary code on machines that load them. Zafran Labs researchers Gal Zaban and Ido Shani identified the vulnerabilities, collectively named FaceHugger, as bypassing the trust_remote_code safeguard designed to stop unreviewed code from running.

- Advertisement -

The root cause stems from a Time-of-Check to Time-of-Use (TOCTOU) flaw in the model download process, which uses two sequential, non-atomic HTTP requests. Consequently, an attacker can modify the repository configuration between the two requests to inject malicious code.

The three vulnerabilities include CVE-2026-44827 (CVSS 8.8), a code injection flaw allowing arbitrary code loading through a crafted pipeline named “None.py” despite trust_remote_code=False. CVE-2026-45804 (CVSS 7.5) is a race condition that introduces arbitrary code by altering the configuration between HTTP calls. CVE-2026-44513 (CVSS 8.8) similarly enables code injection through the custom_pipeline flow.

The issues were addressed in Diffusers version 0.38.0, released in early May 2026. “The underlying problem is that artifacts pulled from AI repositories are frequently treated as passive data,” the researchers added, noting that configuration files and custom pipeline code can quietly become executable code. Users are advised to only load models from fully trusted sources and inspect local snapshots for unexpected Python files.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bezos, Nvidia Join Forces to Fix Chip Materials Shortage

Bezos Expeditions backed CuspAI in a $450 million Series B round, pushing the Cambridge-based...

New Coldcard attack wave steals 389 Bitcoin; Thorn warns

Galaxy research head Alex Thorn warned Monday of a fourth wave of coordinated thefts...

Coldcard Hack Ongoing: $88M Stolen in Three Waves

Galaxy Research now tracks roughly $88.6 million stolen from approximately 4,585 Coldcard addresses across...

STRC shares stay below $100 par, August dividend holds at 12%

Strategy's STRC preferred shares closed July at $89.46, well below their $100 par value,...

Can Apple Stock Double by 2030?

Apple trades near $295 as debate intensifies over whether the stock can double by...

Must Read

What Is Binance Earn?

As someone who is passionate about cryptocurrency, I am always on the lookout for new opportunities to grow my portfolio. That's why I was...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading