Kryptovalutaticker:
sysadmin från Cyber Security News

Hugging Face Diffusers Vulnerabilities Enable Remote Code Execution Through Malicious AI Models

Guru Baran
6 hours ago
10 Visningar
0 Kommentarer
Hugging Face Diffusers Vulnerabilities Enable Remote Code Execution Through Malicious AI Models

A set of high-severity vulnerabilities in Hugging Face’s diffusers library that allow a malicious model repository to silently execute arbitrary code on any machine that loads it. The flaws bypass trust_remote_code, the very safeguard designed to stop unreviewed code from running during the custom pipeline loading process, raising serious concerns for an AI ecosystem that has come to treat Hugging Face as foundational infrastructure. Hugging Face has rapidly evolved into what many call the “GitHub of the AI era,” with its libraries and repositories deeply embedded in development, research, and production environments worldwide. Because diffusers runs inside production pipelines, CI/CD systems, and container...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!