Hugging Face Diffusers Vulnerabilities Enable Remote Code Execution Through Malicious AI Models
03/08/2026-18:01 03/08/2026-18:05 מחשבים וטכנולוגיה Cyber Security News דיווח
A set of high-severity vulnerabilities in Hugging Face’s diffusers library that allow a malicious model repository to silently execute arbitrary code on any machine that loads it. The flaws bypass trust_remote_code, the very safeguard designed to sto
סיכום מאמר"פגיעות בספריית Hugging Face Diffusers מאפשרות ריצה של קוד רחוק דרך דגמי AI מזויפים. תקלות בספריית Hugging Face Diffusers, המשמשת לפיתוח דגמי AI, מאפשרות לדגם מזויף לריצת קוד רחוק על כל מחשב שמעלה אותו. הפגיעות, שהתגלו בספריית Diffusers, חוצות את הבטיחות 'trust_remote_code', שנועדה למנוע ריצת קוד רחוק.תוכן זה נוצר על ידי בינה מלאכותית.