logo

Critical Bugs Put Hugging Face AI Platform in a 'Pickle'

ID: 8c704186-5a71-5953-b0c8-b138c67617f5

STIX ID: report--8c704186-5a71-5953-b0c8-b138c67617f5

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-04-05

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Wiz researchers discovered and demonstrated two critical security flaws in Hugging Face's inference stack: allowing Pickle-based models to execute arbitrary code (enabling reverse shells and exploration of the EKS-hosted environment that could lead to cross-tenant access to secrets) and the ability during Spaces build-time to access and potentially overwrite images in a shared container registry—raising supply-chain and model/data integrity risks; Hugging Face says it has mitigated the issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.