Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
The Hacker News
Read full postResearchers disclosed three high-severity security flaws in Hugging Face's Diffusers library that enable malicious model repositories to execute arbitrary code on users' machines. The vulnerabilities bypass the 'trust_remote_code' safeguard due to a time-of-check to time-of-use (TOCTOU) flaw in the model loading process. Diffusers, widely used for pretrained diffusion models, has been downloaded over 8 million times in July 2026, raising significant AI supply chain security concerns.


