Researchers disclosed three high-severity vulnerabilities in Hugging Face’s Diffusers library that allow a crafted model repository to bypass the trust_remote_code safeguard and execute arbitrary code when a model is loaded. The issues, collectively dubbed FaceHugger, affect workflows using DiffusionPipeline.from_pretrained with custom pipelines and stem from time-of-check to time-of-use flaws in the model download and loading process, where trust validation occurs before later content can be swapped or injected through non-atomic HTTP requests.
The disclosure names CVE-2026-44827, CVE-2026-45804, and variants grouped under CVE-2026-44513, and also points to a related trust issue in Hugging Face’s Transformers library involving pinned commit hash propagation. Because Diffusers is widely used in production AI pipelines, CI/CD environments, and containerized workloads, successful exploitation could turn a routine model pull into an enterprise initial-access vector. The vulnerabilities were patched in Diffusers 0.38.0, and defenders are being urged to upgrade, pin repository revisions, and treat AI model repositories as untrusted executable content.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A July 2026 Hugging Face incident involved a malicious dataset abusing two code-execution paths in the platform's data-processing pipeline. The attacker reportedly executed code on a worker, escalated to node-level access, harvested cloud and cluster credentials, and moved laterally into internal clusters, though Hugging Face found no evidence that public models, datasets, or container images were altered.
Hugging Face addressed the three Diffusers vulnerabilities collectively dubbed FaceHugger in Diffusers version 0.38.0. The fix moved security checks to the dynamic-module loading chokepoint to close the identified bypass variants.
The research also disclosed a similar vulnerability in Hugging Face's Transformers library. According to the report, the issue stems from failure to propagate a pinned commit hash after trust_remote_code approval.
Zafran Labs researchers Gal Zaban and Ido Shani published analysis of three high-severity Diffusers vulnerabilities—CVE-2026-44827, CVE-2026-45804, and CVE-2026-44513—that let crafted model repositories bypass trust_remote_code and execute arbitrary code during model loading. The disclosure traced the issue to Time-of-Check to Time-of-Use flaws in Diffusers' non-atomic model download and loading flow.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourceinfosecurity-magazine.com
Open sourcezafran.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.