logo

Wiz Research finds architecture risks that may compromise AI-as-a-Service providers and consequently risk customer data; works with Hugging Face on mitigations

ID: 1568689f-aeae-51e0-b73e-6a8cc8e7dad1

STIX ID: report--1568689f-aeae-51e0-b73e-6a8cc8e7dad1

Feed Name: Wiz Blog

Threat Score
78/100

Date Published: 2024-04-04

Date Updated: 2026-05-01

...
...

Wiz Research demonstrated that untrusted AI artifacts and build artifacts in Hugging Face could be abused to achieve remote code execution and multi-tenant compromise: a malicious Pickle-serialized PyTorch model executed code during inference, a crafted Dockerfile executed during build, and from those shells researchers accessed EKS node metadata to obtain credentials and Kubernetes tokens, enumerate secrets, and found write access to a shared internal container registry — together creating cross-tenant, supply-chain and sensitive-data exposure risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.