BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

FaceHugger flaws in Hugging Face Diffusers allow AI supply chain attacks

Three FaceHugger flaws in Hugging Face Diffusers allow code execution, bypassing safeguards.

  • Three high-severity vulnerabilities, collectively named FaceHugger, were disclosed in Hugging Face’s Diffusers library, allowing arbitrary code execution on machines that load crafted model repositories.
  • The flaws bypass the trust_remote_code safeguard, which is designed to prevent unreviewed code from running during custom pipeline loading.
  • Attackers can exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition due to the model download being split into two non-atomic HTTP requests.
  • The vulnerabilities were patched in Diffusers version 0.38.0 (released May 2026), and users are advised to only load models from trusted, audited sources.

Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library, enabling crafted model repositories to stealthily execute arbitrary code on machines that load them. Zafran Labs researchers Gal Zaban and Ido Shani identified the vulnerabilities, collectively named FaceHugger, as bypassing the trust_remote_code safeguard designed to stop unreviewed code from running.

- Advertisement -

The root cause stems from a Time-of-Check to Time-of-Use (TOCTOU) flaw in the model download process, which uses two sequential, non-atomic HTTP requests. Consequently, an attacker can modify the repository configuration between the two requests to inject malicious code.

The three vulnerabilities include CVE-2026-44827 (CVSS 8.8), a code injection flaw allowing arbitrary code loading through a crafted pipeline named “None.py” despite trust_remote_code=False. CVE-2026-45804 (CVSS 7.5) is a race condition that introduces arbitrary code by altering the configuration between HTTP calls. CVE-2026-44513 (CVSS 8.8) similarly enables code injection through the custom_pipeline flow.

The issues were addressed in Diffusers version 0.38.0, released in early May 2026. “The underlying problem is that artifacts pulled from AI repositories are frequently treated as passive data,” the researchers added, noting that configuration files and custom pipeline code can quietly become executable code. Users are advised to only load models from fully trusted sources and inspect local snapshots for unexpected Python files.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

CFTC crypto market rule: leverage triggers federal oversight

The CFTC published an advance notice outlining Regulation CTX and Regulation CAM, which would...

BitMine Chairman Touts Largest Crypto Treasury Buyback

BitMine Immersion Technologies purchased 15,112 ETH last week, its smallest weekly buy since mid-August,...

Hiero SDK adds native MirrorNodeAccountBalanceQuery for HBAR

Hedera has introduced MirrorNodeAccountBalanceQuery in the JavaScript, Java, and Go Hiero SDKs as a...

Live Nation doubles CEO pay to $60M despite monopoly verdict

Live Nation approved a contract doubling CEO Michael Rapino’s annual compensation target to over...

Metaplanet adopts net interest strategy to fuel Bitcoin

Metaplanet is adopting a net interest income strategy, keeping Bitcoin as 85%-90% of total...

Must Read

How to Buy VPS with Crypto from Hostinger – Step by Step guide

Did you know that nowadays you can use Bitcoin to purchase a Windows VPS? If you’re here, you’re probably wondering how to do it....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading