Hugging Face Diffusers Vulnerabilities Enable Remote Code Execution Through Malicious AI Models

A set of high-severity vulnerabilities in Hugging Face’s diffusers library that allow a malicious model repository to silently execute arbitrary code on any machine that loads it. The flaws bypass trust_remote_code, the very safeguard designed to stop unreviewed code from running during the custom pipeline loading process, raising serious concerns for an AI ecosystem that […]

This article has been indexed from Cyber Security News

Read the original article: