Vulnerabilities & Exploits · Supply Chain
Model Repos Now Behave Like Code in Diffusers Diffusers treats a model repository as data until load time, and these flaws let that boundary fail. A repo a team meant to inspect can still cross into executable code during model loading, so the normal trust model for AI artifacts breaks inside pipelines, CI jobs, and containers.
Zafran reported three high-severity CVEs in Hugging Face diffusers that bypass trust_remote_code, and Hugging Face fixed them in diffusers 0.38.0 . The issue affects vulnerable versions of a library with roughly seven million downloads a month, including production AI systems that pull third-party models.
The practical risk is not limited to one bad model file. If model loading can invoke attacker-controlled code, the repository itself becomes part of the software supply chain, and patching the library is only useful if teams also verify what they load and where they load it.
2 sources · Aug 3
CVE-2026-44513 NVD KEV
CVSS 8.8 HIGH: diffusers is the a library for pretrained diffusion models. EPSS 0.9% (58th percentile).
CVE-2026-44827 NVD KEV
CVSS 8.8 HIGH: diffusers is the a library for pretrained diffusion models. EPSS 0.7% (51st percentile).
CVE-2026-45804 NVD KEV
CVSS 7.5 HIGH: diffusers is the a library for pretrained diffusion models. EPSS 0.4% (28th percentile).
Timeline Sources Aug 3 The Hacker News
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three Hugging Face Diffusers flaws bypass trust_remote_code, letting crafted model repositories execute code during custom pipeline loading.
original Jul 28 Infosecurity Magazine
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it
original Part of the PlainSec briefing for 2026-08-03
Every edition of this story: Model Repos Now Behave Like Code in Diffusers
More from today
Vulnerabilities & Exploits · Supply Chain
Model Repos Now Behave Like Code in Diffusers Diffusers treats a model repository as data until load time, and these flaws let that boundary fail. A repo a team meant to inspect can still cross into executable code during model loading, so the normal trust model for AI artifacts breaks inside pipelines, CI jobs, and containers.
Zafran reported three high-severity CVEs in Hugging Face diffusers that bypass trust_remote_code, and Hugging Face fixed them in diffusers 0.38.0 . The issue affects vulnerable versions of a library with roughly seven million downloads a month, including production AI systems that pull third-party models.
The practical risk is not limited to one bad model file. If model loading can invoke attacker-controlled code, the repository itself becomes part of the software supply chain, and patching the library is only useful if teams also verify what they load and where they load it.
2 sources · Aug 3
CVE-2026-44513 NVD KEV
CVSS 8.8 HIGH: diffusers is the a library for pretrained diffusion models. EPSS 0.9% (58th percentile).
CVE-2026-44827 NVD KEV
CVSS 8.8 HIGH: diffusers is the a library for pretrained diffusion models. EPSS 0.7% (51st percentile).
CVE-2026-45804 NVD KEV
CVSS 7.5 HIGH: diffusers is the a library for pretrained diffusion models. EPSS 0.4% (28th percentile).
Timeline Sources Aug 3 The Hacker News
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three Hugging Face Diffusers flaws bypass trust_remote_code, letting crafted model repositories execute code during custom pipeline loading.
original Jul 28 Infosecurity Magazine
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Three CVEs in Hugging Face diffusers let a malicious model repo run code on any machine that loads it
original Part of the PlainSec briefing for 2026-08-03
Every edition of this story: Model Repos Now Behave Like Code in Diffusers
More from today