Hugging Face Transformers RCE flaw enables stealthy compromise via AI model configs (opens in new tab)
A high severity vulnerability in Hugging Face Transformers enables attackers to compromise systems that use the popular Python library to test and run AI models. The flaw impacts library versions that continue to be actively downloaded and comes at a time when attackers are increasingly , including through malicious models hosted on the Hugging Face platform. The exploit for this vulnerability involves adding an innocuous-looking parameter called _attn_implementation_internal to remote model ...
Read the original article