« Volver al listado

CVE-2026-44513

Estado: ModificadaAlta (8.8)—

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulnerability has three variants, all sharing the same root cause — the trust_remote_code gate was implemented inside DiffusionPipeline.download() rather than at the actual dynamic-module load site, so any code path that bypassed or short-circuited download() also bypassed the security check.

Leer descripción completaMostrar menos

DiffusionPipeline.from_pretrained('repoA', custom_pipeline='attacker/repoB', trust_remote_code=False) — the gate evaluated against repoA's file list rather than repoB's, so repoB's pipeline.py was loaded and executed. DiffusionPipeline.from_pretrained('/local/snapshot', custom_pipeline='attacker/repoB', trust_remote_code=False) — the local-path branch never invoked download(), so the gate was never reached and remote code from repoB executed. DiffusionPipeline.from_pretrained('/local/snapshot', trust_remote_code=False) where the snapshot contains custom component files (e.g. unet/my_unet_model.py) referenced from model_index.json — same root cause; the local path skipped download() and custom component code executed. This vulnerability is fixed in 0.38.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

UI:R (requiere interacción del usuario al cargar modelos) determina T1203. CWE-94 (ejecución dinámica de código) y bypass de trust_remote_code permiten ejecutar código arbitrario remoto al llamar from_pretrained con parámetros maliciosos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-44513",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-44513",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-14T17:38:51.150920Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "huggingface",
          "product": "diffusers",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.38.0"
            }
          ]
        }
      ]
    },
    {
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "affectedData": [
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787077779",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787076481",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1786611803",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-training-cuda128-torch29-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1786611435",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-training-rocm64-torch29-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ai_inference_server:3"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat AI Inference Server",
          "packageName": "rhaiis/vllm-cpu-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ai_inference_server:3"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat AI Inference Server",
          "packageName": "rhaiis/vllm-cuda-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ai_inference_server:3"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat AI Inference Server",
          "packageName": "rhaiis/vllm-rocm-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ai_inference_server:3"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat AI Inference Server",
          "packageName": "rhaiis/vllm-tpu-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ai_inference_server:3"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat AI Inference Server",
          "packageName": "rhaii/vllm-cpu-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:ai_inference_server:3"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat AI Inference Server",
          "packageName": "rhaii/vllm-cuda-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux_ai:3"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux AI (RHEL AI) 3",
          "packageName": "rhelai3/bootc-aws-cuda-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux_ai:3"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux AI (RHEL AI) 3",
          "packageName": "rhelai3/bootc-azure-cuda-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux_ai:3"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux AI (RHEL AI) 3",
          "packageName": "rhelai3/bootc-cuda-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:enterprise_linux_ai:3"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Enterprise Linux AI (RHEL AI) 3",
          "packageName": "rhelai3/bootc-gcp-cuda-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "packageName": "rhoai/odh-openvino-model-server-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "packageName": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-14T17:16:22.903",
  "references": [
    {
      "url": "https://github.com/huggingface/diffusers/security/advisories/GHSA-98h9-4798-4q5v",
      "tags": [
        "Exploit",
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:60520",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-44513",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2477507",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44513.json",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "description": [
        {
          "lang": "en",
          "value": "CWE-358"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Diffusers is the a library for  pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulnerability has three variants, all sharing the same root cause — the trust_remote_code gate was implemented inside DiffusionPipeline.download() rather than at the actual dynamic-module load site, so any code path that bypassed or short-circuited download() also bypassed the security check. DiffusionPipeline.from_pretrained('repoA', custom_pipeline='attacker/repoB', trust_remote_code=False) — the gate evaluated against repoA's file list rather than repoB's, so repoB's pipeline.py was loaded and executed. DiffusionPipeline.from_pretrained('/local/snapshot', custom_pipeline='attacker/repoB', trust_remote_code=False) — the local-path branch never invoked download(), so the gate was never reached and remote code from repoB executed. DiffusionPipeline.from_pretrained('/local/snapshot', trust_remote_code=False) where the snapshot contains custom component files (e.g. unet/my_unet_model.py) referenced from model_index.json — same root cause; the local path skipped download() and custom component code executed. This vulnerability is fixed in 0.38.0."
    }
  ],
  "lastModified": "2026-08-28T16:18:07.723",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:huggingface:diffusers:*:*:*:*:*:python:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7F2A2AE-D122-46BA-BD64-67DCF4C22677",
              "versionEndExcluding": "0.38.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}