Hugging Face Diffusers Vulnerabilities Enable Arbitrary Code Execution
Security researchers disclosed multiple flaws in Hugging Face's Diffusers library that could allow malicious model repositories to execute arbitrary code when loaded. The vulnerabilities stem from unsafe deserialization and mishandled pickle files. Users are urged to update to patched versions to prevent supply-chain attacks.