THE article discusses significant security flaws in Hugging Face's diffusers library that allow crafted model repositories to execute arbitrary code during loading processes, thus circumventing existing safeguards. Three high-severity vulnerabilities, reported by Zafran Security, expose the system to potential supply chain attacks, with the flaws being rooted in timing discrepancies between security checks and code execution.
These issues affect a library that is widely used in AI pipelines, leading to concerns regarding the execution of unverified code. Hugging Face has since addressed these vulnerabilities in a patch released in May 2026.