BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

FaceHugger flaws in Hugging Face Diffusers allow AI supply chain attacks

Three FaceHugger flaws in Hugging Face Diffusers allow code execution, bypassing safeguards.

  • Three high-severity vulnerabilities, collectively named FaceHugger, were disclosed in Hugging Face’s Diffusers library, allowing arbitrary code execution on machines that load crafted model repositories.
  • The flaws bypass the trust_remote_code safeguard, which is designed to prevent unreviewed code from running during custom pipeline loading.
  • Attackers can exploit a Time-of-Check to Time-of-Use (TOCTOU) race condition due to the model download being split into two non-atomic HTTP requests.
  • The vulnerabilities were patched in Diffusers version 0.38.0 (released May 2026), and users are advised to only load models from trusted, audited sources.

Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library, enabling crafted model repositories to stealthily execute arbitrary code on machines that load them. Zafran Labs researchers Gal Zaban and Ido Shani identified the vulnerabilities, collectively named FaceHugger, as bypassing the trust_remote_code safeguard designed to stop unreviewed code from running.

- Advertisement -

The root cause stems from a Time-of-Check to Time-of-Use (TOCTOU) flaw in the model download process, which uses two sequential, non-atomic HTTP requests. Consequently, an attacker can modify the repository configuration between the two requests to inject malicious code.

The three vulnerabilities include CVE-2026-44827 (CVSS 8.8), a code injection flaw allowing arbitrary code loading through a crafted pipeline named “None.py” despite trust_remote_code=False. CVE-2026-45804 (CVSS 7.5) is a race condition that introduces arbitrary code by altering the configuration between HTTP calls. CVE-2026-44513 (CVSS 8.8) similarly enables code injection through the custom_pipeline flow.

The issues were addressed in Diffusers version 0.38.0, released in early May 2026. “The underlying problem is that artifacts pulled from AI repositories are frequently treated as passive data,” the researchers added, noting that configuration files and custom pipeline code can quietly become executable code. Users are advised to only load models from fully trusted sources and inspect local snapshots for unexpected Python files.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Study: Crypto owners expect 22% returns, causing volatility

A Cleveland Fed working paper finds crypto ownership is driven more by return expectations...

Nvidia vs Micron: Growth Gap Highlights AI Stock Valuation Divide

Micron stock surged 253.9% year-to-date against NVIDIA's 20.7% gain, flipping the valuation debate between...

ACE Robotics CEO Predicts Robot ‘ChatGPT Moment’ by 2027

ACE Robotics Chairman Wang Xiaogang predicts embodied AI could reach its "ChatGPT moment" by...

Bitcoin’s 26% Rally Wipes Out $3.1B in Shorts

Bitcoin surged 26% from $62,900 to $79,500 in five days, liquidating $3.1 billion in...

Microsoft Entra ID bug gets perfect 10.0 CVSS score

Microsoft disclosed a critical remote code execution vulnerability in its Entra ID cloud identity...

Must Read

14 Ways On How to Make Money with Cryptocurrency

Many people want to make money with cryptocurrency because they have heard the success stories of people who became millionaires from zero.If you...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading