Three high-severity flaws in Hugging Face Diffusers library allow arbitrary code execution via crafted model repositories
Three security vulnerabilities have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the AI supply chain to risk.