High severity7.5GHSA Advisory· Published Jul 15, 2026· Updated Aug 12, 2026
CVE-2026-45804
CVE-2026-45804
Description
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change, allowing a Hub repository with custom .py pipeline code to execute through the custom pipeline flow without passing custom_pipeline or trust_remote_code=True. This issue is fixed in version 0.38.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
diffusersPyPI | < 0.38.0 | 0.38.0 |
Affected products
6< 0.38.0+ 1 more
- (no CPE)range: < 0.38.0
- cpe:2.3:a:huggingface:diffusers:*:*:*:*:*:python:*:*range: <0.38.0
- osv-coords4 versionspkg:apk/chainguard/py3.12-diffusers-cuda-13.0pkg:apk/chainguard/py3.11-diffusers-cuda-12.9pkg:apk/chainguard/py3.13-diffusers-cuda-13.0pkg:apk/chainguard/py3.11-diffusers-cuda-13.0
< 0.38.0-r0+ 3 more
- (no CPE)range: < 0.38.0-r0
- (no CPE)range: < 0.38.0-r0
- (no CPE)range: < 0.38.0-r0
- (no CPE)range: < 0.38.0-r0
Patches
Vulnerability mechanics
References
8- github.com/huggingface/diffusers/commit/a37f6f8394ac2a7ee8360c3abea811efe54512b1nvdPatchWEB
- github.com/huggingface/diffusers/issues/13446nvdIssue TrackingExploitWEB
- github.com/advisories/GHSA-7wx4-6vff-v64pghsaADVISORY
- github.com/huggingface/diffusers/security/advisories/GHSA-7wx4-6vff-v64pnvdVendor AdvisoryExploitWEB
- nvd.nist.gov/vuln/detail/CVE-2026-45804ghsaADVISORY
- github.com/huggingface/diffusers/pull/13448nvdIssue TrackingWEB
- github.com/huggingface/diffusers/releases/tag/v0.38.0nvdRelease NotesWEB
- github.com/pypa/advisory-database/tree/main/vulns/diffusers/PYSEC-2026-2446.yamlghsaWEB
News mentions
4- Hugging Face Diffusers Vulnerabilities Enable Remote Code Execution Through Malicious AI ModelsCyber Security News · Aug 3, 2026
- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026
- Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary CodeThe Hacker News · Aug 3, 2026
- Bugs in Hugging Face Diffusers Bypass Custom Code SafeguardInfosecurity Magazine · Jul 28, 2026