Infosecurity reports that three high-severity flaws in Hugging Face’s open-source diffusers library let crafted model repositories bypass trust_remote_code protections and execute arbitrary code during affected loading flows.
Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard
Infosecurity reports that three high-severity flaws in Hugging Face's open-source diffusers library let crafted model repositories bypass trust_remote_code protections and execute arbitrary code during affected loading flows.
Source: Infosecurity Magazine