Lead dispatch
First reported zafran.io
FaceHugger: Hugging Face Diffusers Flaws Open Door to AI Supply Chain Attacks
Zafran Labs disclosed a set of high-severity vulnerabilities (CVE-2026-44827 CVSS 8.8, CVE-2026-45804 CVSS 7.5, and CVE-2026-44513 CVSS 8.8) in Hugging Face's widely used diffusers library that let a malicious model repository silently execute arbitrary code on any client that loads it. The root cause is a Time-of-Check to Time-of-Use (TOCTOU) flaw: a model download is split into two non-atomic HTTP requests, and the trust_remote_code safeguard is only enforced against the first, allowing the check to be bypassed. The write-up ties the flaw to a July 2026 Hugging Face intrusion in which a malicious dataset abused dataset-processing code-execution paths.supply-chain · code-injection · arbitrary-code-execution · toctou · model-loading-abuse
hugging-face · diffusers · ai-supply-chain · llm · ml-models
Severity
0.82
The wire · latest
See the API docs to pull all 442 items →How the wire is made
Poll & cluster
Internet is crawled for AI security news and near-duplicate coverage is embedded and grouped into durable items.
Curate
AI Agent filters for agentic-AI relevance, classifies and tags each item, scores severity for threats, and writes the summary.
Every item here is one machine-curated intelligence object, not a headline.
Read the wire for free. There is a small charge to ask the index questions.
The wire, open
The complete curated feed, no key required.
- GET /feed.xml — RSS 2.0, every item
- GET /api/items — read-only
The vector desk
Query the index by meaning, not just keyword.
- GET /api/items?tags=&minSeverity=&itemType=
- GET /api/search?q= — keyword
- GET /api/semantic?q= — vector