{"id":"CVE-2026-45804","title":"diffusers: Diffusers: Arbitrary code execution due to trust_remote_code guard bypass (CVE-2026-45804)","summary":"A flaw was found in Diffusers, a library for pretrained diffusion models. A remote attacker could exploit this vulnerability by crafting a malicious Hub repository with custom Python pipeline code. The `DiffusionPipeline.from_pretrained` f…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-94","vendor":"Red Hat","product":"Red Hat OpenShift AI 3.4","affected":["ai_inference_server","enterprise_linux_ai_rhel_ai 3","ai_inference_server 3.4","openshift_ai 3.4"],"patched":["ai_inference_server 3.4","openshift_ai 3.4"],"published":"2026-07-15","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:33:50+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45804.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45804.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-45804"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2501024"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-45804"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45804"},{"url":"https://github.com/huggingface/diffusers/commit/a37f6f8394ac2a7ee8360c3abea811efe54512b1"},{"url":"https://github.com/huggingface/diffusers/issues/13446"},{"url":"https://github.com/huggingface/diffusers/pull/13448"},{"url":"https://github.com/huggingface/diffusers/releases/tag/v0.38.0"},{"url":"https://github.com/huggingface/diffusers/security/advisories/GHSA-7wx4-6vff-v64p"},{"url":"https://access.redhat.com/errata/RHSA-2026:69466"},{"url":"https://access.redhat.com/errata/RHSA-2026:69467"},{"url":"https://access.redhat.com/errata/RHSA-2026:60520"},{"url":"https://github.com/huggingface/diffusers"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/diffusers/PYSEC-2026-2446.yaml"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00376,"epssPercentile":0.31404,"aliases":["GHSA-7wx4-6vff-v64p","PYSEC-2026-2446"],"ecosystem":"pip","ingestedAt":"2026-07-13T18:57:54.749Z","slug":"CVE-2026-45804","body":"## Overview\n\nA flaw was found in Diffusers, a library for pretrained diffusion models. A remote attacker could exploit this vulnerability by crafting a malicious Hub repository with custom Python pipeline code. The `DiffusionPipeline.from_pretrained` flow can bypass the `trust_remote_code` security mechanism, allowing the execution of arbitrary code on the system when a user interacts with the malicious repository. This could lead to high impact on confidentiality, integrity, and availability of the affected system.\n\n## Vendor advisories\n\n- **RHSA-2026:69466** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69466)\n- **RHSA-2026:69467** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69467)\n- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)\n- **Red Hat VEX** · Important · affected: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3 · no fix planned: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45804.json)\n\n**diffusers: Diffusers: Arbitrary code execution due to trust_remote_code guard bypass** — rated Important by Red Hat. Released 2026-07-15, updated 2026-09-21.\n\nAffected:\n\n- Red Hat AI Inference Server\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n\nFixed:\n\n- Red Hat AI Inference Server 3.4\n- Red Hat OpenShift AI 3.4\n\nNo fix planned:\n\n- Red Hat AI Inference Server\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n\nNot affected:\n\n- Red Hat OpenShift AI 3.4\n- Red Hat AI Inference Server\n- Red Hat OpenShift AI (RHOAI)\n\n## Remediation\n\nFor more information visit https://access.redhat.com/errata/RHSA-2026:69466 https://access.redhat.com/errata/RHSA-2026:69466\nFor more information visit https://access.redhat.com/errata/RHSA-2026:69467 https://access.redhat.com/errata/RHSA-2026:69467\nFor Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:60520\n\n## Package advisory (CVE-2026-45804)\n\nAffected packages:\n\n- `diffusers < 0.38.0`\n\nPatched in:\n\n- `diffusers 0.38.0`\n\nSource: https://osv.dev/vulnerability/GHSA-7wx4-6vff-v64p","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}