logo

Popular Python libraries used in Hugging Face models subject to poisoned metadata attack

ID: 0aa7e394-c5a9-5950-a721-83370cbb109f

STIX ID: report--0aa7e394-c5a9-5950-a721-83370cbb109f

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-01-13

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

**Executive summary:** Multiple popular AI/ML Python libraries (NeMo, Uni2TS, FlexTok) misuse Hydra's hydra.utils.instantiate() when loading model metadata, enabling remote code execution via malicious metadata embedded in model files on repositories like Hugging Face; Unit 42 reported the issues, maintainers released fixes and CVEs, and although no active exploitation has been observed, the large number of affected models creates a significant attack surface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.