Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-45804
CVE
CVE-2026-45804
View on NVD ↗
Diffusers: TOCTOU Trust Remote Code Bypass
MITRE ATT&CK TTPs
3
T1059.003
Windows Command Shell
Execution
T1078
Valid Accounts
Defense Evasion
T1210
Exploitation of Remote Services
Lateral Movement
Source Articles
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity vulnerabilities in Hugging Face's Diffusers library, collectively named FaceHugger, allow attackers to bypass the trust_remote_code safeguard and execute arbitrary code when loading models from untrusted repositories. The flaws stem from TOCTOU race conditions and improper validation during model loading, enabling malicious model repositories to silently run code during pipeline initialization. These vulnerabilities affect systems that use DiffusionPipeline.from_pretrained with untrusted or remote custom pipelines, posing significant AI supply chain risks.
hacker-news
Aug 3, 2026