INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Hugging Face Diffusers Flaws Allow Arbitrary Code Execution
| 2026-08-03 06:40 CRITICAL MEDIUM VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The vulnerabilities disclosed in Hugging Face's Diffusers library pose a significant threat to the artificial intelligence (AI) supply chain, allowing attackers to execute arbitrary code on compromised machines. The flaws are categorized as high-severity security issues with CVSS scores ranging from 7.5 to 8.8, indicating their potential impact and severity. These vulnerabilities exploit weaknesses in custom pipeline configuration files, enabling attackers to inject malicious code into production pipelines, CI/CD systems, and container images. As a result, organizations relying on Hugging Face's libraries should take immediate action to address these issues and ensure the integrity of their AI infrastructure.
Technical Mitigations AI-generated
I can provide you with 3-5 technical mitigations in bullet points based on the articles:
* Verify repository trust: Before loading a model from a Hugging Face hub repository, ensure that the repository has been audited and is fully trusted. This can be done by checking the repository's configuration files, loaders, and custom pipeline code for any suspicious activity.
* Use pretrained_model_name_or_path with caution: When using `from_pretrained()` to load models from a Hugging Face hub repository, make sure to specify `pretrained_model_name_or_path` instead of just `pretrained`. This can help prevent arbitrary code execution if the custom pipeline is not properly configured.
* Avoid passing custom_pipeline: Be cautious when passing `custom_pipeline` as an argument to `from_pretrained()`, especially in vulnerable versions of Hugging Face's diffusers library. If possible, use a different approach or wait for a patch to be released before using this feature.
* Monitor model repository activity: Keep track of the models you load from repositories and monitor their activity over time. This can help identify any suspicious patterns that may indicate code injection vulnerabilities.
* Use secure download mechanisms: When downloading models from Hugging Face hub repositories, use secure download mechanisms such as HTTPS or SFTP to prevent data exfiltration and ensure that only trusted sources are accessed.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
No•••••.py
pi•••••.py
pe•••••.tech
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-45804CVE-2026-45804
CVE-2026-44513CVE-2026-44513
CVE-2026-44827CVE-2026-44827
Target & Sectors
Global Scope
Incident Timeline
March 19
Threat actors exploited vulnerabilities in Hugging Face Diffusers to target model repositories.
May 1
Hugging Face released diffusers 0.38.0 on May 1, which updated the dynamic-module loading step to prevent potential security flaws that could allow arbitrary code execution in model repositories.
Click on any entity below to view its context and source!
infrastructure
0.38.0
Hugging Face released diffusers 0.38.0 on May 1, moving the security checks to the dynamic-module loading step and closing the identified variants.
early May 2026
Threat actors exploited flaws in Hugging Face Diffusers, a model repository software, allowing them to execute arbitrary code.
Click on any entity below to view its context and source!
infrastructure
0.38.0
Following responsible disclosure, the vulnerabilities were addressed in Diffusers version 0.38.0, released in early May 2026.
May 2026
Threat actors used Hugging Face's model repositories to exploit vulnerabilities in the company's diffusers by calling from_pretrained with custom_pipeline and local snapshot directories from untrusted sources.
Click on any entity below to view its context and source!
organisation
pretrained_model_name_or_path
If immediate patching is not an option, the project maintainers have recommended the following workarounds -
Only call from_pretrained with pretrained_model_name_or_path, custom_pipeline, and local snapshot directories from fully trusted sources that have been audited.
organisation
Hugging Face
"These vulnerabilities underscore the critical need to treat AI model repositories as untrusted code, particularly as enterprise reliance on platforms like Hugging Face continues to grow," Zafran said.
July 2026
Threat actors exploited a race condition vulnerability in Hugging Face Diffusers to introduce arbitrary code into model repositories by modifying configuration between the hf_hub_download and snapshot_download HTTP calls.
Click on any entity below to view its context and source!
organisation
pepy.tech
According to statistics shared on pepy.tech, the package has been
downloaded
more than 8.1 million times in July 2026.
general_metric
8.1 Downloads / Installs
According to statistics shared on pepy.tech, the package has been
downloaded
more than 8.1 million times in July 2026.
organisation
CVE-2026
CVE-2026-44513
(CVSS score: 8.8) -
organisation
DiffusionPipeline
API
One of the key capabilities of the library is to locally load a model from a Hugging Face hub repository via the
DiffusionPipeline
API, which, in turn, makes use of a configuration file to initialize specific pipeline and component classes, along with custom pipeline code.
organisation
Hub
A race condition vulnerability that allows arbitrary code to be introduced to a repository by modifying the configuration between the hf_hub_download and snapshot_download HTTP calls to the Hub, leading to code execution.
2026/07/27
Threat actors exploited a flaw in Hugging Face's diffusers to gain access to model repositories by bypassing the trust_remote_code safeguard.
July 27
Threat actors exploited flaws in the hugging face diffusers to execute arbitrary code.
Click on any entity below to view its context and source!
organisation
Zafran Security
According to
research
from threat exposure management firm Zafran Security published on July 27, the flaws defeated trust_remote_code, the check meant to stop unreviewed code running when a model is fetched.
Aug 03, 2026
Threat actors used a flaw in the Hugging Face Diffusers library to target its model repositories, allowing them to execute arbitrary code.
Click on any entity below to view its context and source!
organisation
FaceHugger
The shortcomings have been collectively named
FaceHugger
.
organisation
CI
With Hugging Face becoming the "GitHub of the AI era" and its libraries and repositories prevalent in enterprise environments, vulnerabilities in libraries like Diffusers can grant attackers extensive access owing to how the library is embedded into production pipelines, CI/CD systems, and container images.
2026/08/03
The Hugging Face Diffusers library exploited vulnerabilities (CVE-2026-44827 and CVE-2026-45804) in its code that allowed crafted model repositories to silently execute arbitrary code during loading flows.
Click on any entity below to view its context and source!
organisation
CVE-2026-44827
CVE-2026-44827 (CVSS 8.8) exploited a string-formatting quirk.
organisation
None.py
The check used a different code path and did not flag None.py, so a repository containing that file passes while executing attacker code on load.
organisation
CVE-2026-45804
CVE-2026-45804 (CVSS 7.5) exploited the gap between the two requests.
organisation
CI
The library draws roughly seven million downloads a month, close to 200,000 a day, sitting inside production AI pipelines, CI/CD systems and container images.
infrastructure
200,000 downloads
The library draws roughly seven million downloads a month, close to 200,000 a day, sitting inside production AI pipelines, CI/CD systems and container images.
organisation
Hugging Face
Commenting on the OpenAI incident, Crystal Morin, cybersecurity strategist at AI cloud security firm Sysdig, said what caught the Hugging Face intrusion was "behavioral anomaly detection at the infrastructure level," not perimeter defenses.
organisation
Hugging Face’s
Three high-severity flaws in vulnerable versions of Hugging Face’s diffusers library let crafted model repositories silently execute arbitrary code during affected loading flows, bypassing the safeguard built to prevent exactly that.
organisation
Hugging Face's
The findings land days after
OpenAI's frontier models breached Hugging Face's production infrastructure
, logging over 17,000 events across a weekend.
organisation
Sumo Logic
Jeremy Powell, CISO at log management vendor Sumo Logic, said the defenses that mattered now were "the unglamorous ones": egress control, segmentation and credential hygiene, alongside detection operating at the speed of the attack.
Tactical Metrics
Metrics
infrastructure
0.38.0
Software Version
Click for context!
Following responsible disclosure, the vulnerabilities were addressed in Diffusers version 0.38.0, released in early May 2026.
Hugging Face released diffusers 0.38.0 on May 1, moving the security checks to the dynamic-module loading step and closing the identified variants.
Metrics
infrastructure
200,000
Downloads
The library draws roughly seven million downloads a month, close to 200,000 a day, sitting inside production AI pipelines, CI/CD systems and container images.
Intelligence Sources
Infosecurity-Magazine
2026-07-28
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Infosecurity-Magazine
The Hacker News
2026-08-03
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-03T10:32
Comprehensive Tactical Telemetry
Highly Correlated Entities
15x
organisation
Identified Entity
pepy.tech
entity
8x
timeline
Temporal Reference
Aug 03, 2026
date
3x
vulnerability
Exploited CVE
CVE-2026-44827
cve
2x
attribution
Attributing Entity
Vulnerability / AI Security
authority
2x
vulnerability
CVSS Score
9
score
Contextual Telemetry
Context Block
8 METRICS
general metric
Downloads / Installs
8,100,000
downloads
general metric
Vulnerabilities
9
vulnerabilities
infrastructure
Software Version
0.38.0
version
general metric
Aug
3
aug
tactic
MITRE ATT&CK Technique
T1059.006 - Python
technique
infrastructure
Downloads
200,000
downloads
general metric
Events
17,000
events
general metric
Seconds
0
seconds
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.