Executive brief
Hugging Face Diffusers is a popular library used for running AI models like Stable Diffusion. A security flaw allows a malicious AI model to read sensitive files from the computer or server where the model is being loaded. This could lead to the theft of private data or credentials if a user is tricked into loading a specially crafted model from an untrusted source.
Technical details
A path traversal vulnerability exists in the `_get_checkpoint_shard_files` function within `src/diffusers/utils/hub_utils.py`. The library fails to sanitize shard filenames retrieved from the `weight_map` in a model's index JSON file (`diffusion_pytorch_model.safetensors.index.json`). An attacker can provide a malicious model containing `../` sequences or absolute paths in the `weight_map` values. When a user loads this model using functions like `DiffusionPipeline.from_pretrained`, the library will join these malicious paths with the model directory, allowing the attacker to read arbitrary files (in safetensors format) from the host system. The issue was fixed in commit `cee298c` by validating that shard filenames do not contain directory traversal components.
Affected products
- Hugging Face Diffusers <= 0.39.0
Timeline
- 2026-06-09: disclosed: Initial report to Hugging Face
- 2026-07-12: other: Public GitHub issue opened
- 2026-07-17: patched: Fix merged into main branch
- 2026-07-23: advisory: CVE published