INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Hugging Face Diffusers Flaws Allow Arbitrary Code Execution

| 2026-08-03 06:40 CRITICAL MEDIUM VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The vulnerabilities disclosed in Hugging Face's Diffusers library pose a significant threat to the artificial intelligence (AI) supply chain, allowing attackers to execute arbitrary code on compromised machines. The flaws are categorized as high-severity security issues with CVSS scores ranging from 7.5 to 8.8, indicating their potential impact and severity. These vulnerabilities exploit weaknesses in custom pipeline configuration files, enabling attackers to inject malicious code into production pipelines, CI/CD systems, and container images. As a result, organizations relying on Hugging Face's libraries should take immediate action to address these issues and ensure the integrity of their AI infrastructure.
Technical Mitigations AI-generated
I can provide you with 3-5 technical mitigations in bullet points based on the articles: * Verify repository trust: Before loading a model from a Hugging Face hub repository, ensure that the repository has been audited and is fully trusted. This can be done by checking the repository's configuration files, loaders, and custom pipeline code for any suspicious activity. * Use pretrained_model_name_or_path with caution: When using `from_pretrained()` to load models from a Hugging Face hub repository, make sure to specify `pretrained_model_name_or_path` instead of just `pretrained`. This can help prevent arbitrary code execution if the custom pipeline is not properly configured. * Avoid passing custom_pipeline: Be cautious when passing `custom_pipeline` as an argument to `from_pretrained()`, especially in vulnerable versions of Hugging Face's diffusers library. If possible, use a different approach or wait for a patch to be released before using this feature. * Monitor model repository activity: Keep track of the models you load from repositories and monitor their activity over time. This can help identify any suspicious patterns that may indicate code injection vulnerabilities. * Use secure download mechanisms: When downloading models from Hugging Face hub repositories, use secure download mechanisms such as HTTPS or SFTP to prevent data exfiltration and ensure that only trusted sources are accessed.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

No•••••.py
pi•••••.py
pe•••••.tech
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-45804CVE-2026-45804 CVE-2026-44513CVE-2026-44513 CVE-2026-44827CVE-2026-44827
Target & Sectors
Global Scope
Incident Timeline
‎March 19
Threat actors exploited vulnerabilities in Hugging Face Diffusers to target model repositories.
‎May 1
Hugging Face released diffusers 0.38.0 on May 1, which updated the dynamic-module loading step to prevent potential security flaws that could allow arbitrary code execution in model repositories.
infrastructure 0.38.0
‎early May 2026
Threat actors exploited flaws in Hugging Face Diffusers, a model repository software, allowing them to execute arbitrary code.
infrastructure 0.38.0
‎May 2026
Threat actors used Hugging Face's model repositories to exploit vulnerabilities in the company's diffusers by calling from_pretrained with custom_pipeline and local snapshot directories from untrusted sources.
organisation pretrained_model_name_or_path
organisation Hugging Face
‎July 2026
Threat actors exploited a race condition vulnerability in Hugging Face Diffusers to introduce arbitrary code into model repositories by modifying configuration between the hf_hub_download and snapshot_download HTTP calls.
organisation pepy.tech
general_metric 8.1 Downloads / Installs
organisation CVE-2026
organisation DiffusionPipeline API
organisation Hub
‎2026/07/27
Threat actors exploited a flaw in Hugging Face's diffusers to gain access to model repositories by bypassing the trust_remote_code safeguard.
‎July 27
Threat actors exploited flaws in the hugging face diffusers to execute arbitrary code.
organisation Zafran Security
‎Aug 03, 2026
Threat actors used a flaw in the Hugging Face Diffusers library to target its model repositories, allowing them to execute arbitrary code.
organisation FaceHugger
organisation CI
‎2026/08/03
The Hugging Face Diffusers library exploited vulnerabilities (CVE-2026-44827 and CVE-2026-45804) in its code that allowed crafted model repositories to silently execute arbitrary code during loading flows.
organisation CVE-2026-44827
organisation None.py
organisation CVE-2026-45804
organisation CI
infrastructure 200,000 downloads
organisation Hugging Face
organisation Hugging Face’s
organisation Hugging Face's
organisation Sumo Logic
Tactical Metrics
Metrics
infrastructure
‎0.38.0
Software Version
Metrics
infrastructure
200,000
Downloads
Intelligence Sources
Infosecurity-Magazine 2026-07-28