The record
Written from the 1 report below. Nothing here is unsourced.
- Three high-severity vulnerabilities (CVE-2026-44827, CVE-2026-45804, CVE-2026-44513) were disclosed in Hugging Face's Diffusers library, affecting all versions prior to 0.38.0.
- The flaws allow attackers to bypass the trust_remote_code safeguard in DiffusionPipeline.from_pretrained, enabling arbitrary remote code execution even when users explicitly disable remote code loading.
- The vulnerabilities stem from improper validation of model downloads and custom pipeline references, with CVSS scores of 7.5 and high impact on confidentiality, integrity, and availability.
- Hugging Face released version 0.38.0 to address the issues and recommends immediate patching.
- Organizations using Diffusers in production AI/ML pipelines face significant risk if they load models from untrusted sources or Hub repositories.
- Workarounds include restricting from_pretrained calls to trusted sources only, avoiding custom_pipeline parameters pointing at Hub repositories, and inspecting model snapshots for unexpected .py files.
What to watch next
- Upgrade to Diffusers 0.38.0 immediately
- Audit model loading sources for trust_remote_code bypasses
- Inspect model snapshots for unexpected .py files
- Restrict custom_pipeline parameters to trusted sources only
Why it matters3
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Hugging Face Diffusers users patch required· immediate
- AI/ML development pipelines supply chain risk· days
- Organizations using Diffusers in production remote code execution risk· immediate
Coverage1
1 report
English national1
Filed from United States ×2, India ×1
Named India · Diffusers · Huggingface · Hugging Face · Gal Zaban · Ido Shani · pepy.tech · Zafran Labs
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
