logo

New Hugging Face Vulnerability Exposes AI Models to Supply Chain Attacks

ID: 479c2ca1-585a-5c84-a103-97f65296f478

STIX ID: report--479c2ca1-585a-5c84-a103-97f65296f478

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-02-27

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers found that Hugging Face's Safetensors conversion service can be abused by submitting malicious PyTorch binaries to hijack the conversion bot (SFConvertbot), exfiltrate tokens, and push attacker-controlled pull requests that could compromise or implant backdoors in hosted models—creating a significant supply-chain risk for ML models; the report also calls out the LeftoverLocals GPU memory-leak (CVE-2023-4969) which can expose LLM inputs, outputs, and weights from local memory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.