{"id":"CVE-2026-45804","aliases":["GHSA-7wx4-6vff-v64p","PYSEC-2026-2446"],"url":"https://o3.security/vulnerability/CVE-2026-45804","summary":"Diffusers: TOCTOU Trust Remote Code Bypass","details":"Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change, allowing a Hub repository with custom .py pipeline code to execute through the custom pipeline flow without passing custom_pipeline or trust_remote_code=True. This issue is fixed in version 0.38.0.","published":"2026-07-15T16:05:35.217Z","modified":"2026-08-14T04:03:52.284358046Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":{"score":0.00376,"percentile":0.30806,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"diffusers","fixedVersion":"0.38.0"}],"fix":{"url":"https://github.com/huggingface/diffusers/commit/a37f6f8394ac2a7ee8360c3abea811efe54512b1","label":"huggingface/diffusers@a37f6f8"},"references":[{"type":"WEB","url":"https://github.com/huggingface/diffusers/releases/tag/v0.38.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45804.json"},{"type":"ADVISORY","url":"https://github.com/huggingface/diffusers/security/advisories/GHSA-7wx4-6vff-v64p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45804"},{"type":"REPORT","url":"https://github.com/huggingface/diffusers/issues/13446"},{"type":"FIX","url":"https://github.com/huggingface/diffusers/commit/a37f6f8394ac2a7ee8360c3abea811efe54512b1"},{"type":"FIX","url":"https://github.com/huggingface/diffusers/pull/13448"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-14T04:03:52.284358046Z"}}