Diffusers: None.py Trust Remote Code Bypass
Published May 14, 2026
8.8
HIGHCVSS 3.1
EPSS 0.70%
Description
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hugging Face Hub repositories. The _resolve_custom_pipeline_and_cls function in pipeline_loading_utils.py performs string interpolation on the custom_pipeline parameter using f"{custom_pipeline}.py". When custom_pipeline is not supplied by the user, it defaults to None, which Python interpolates as the literal string "None.py". If an attacker publishes a Hub repository containing a file named None.py with a class that subclasses DiffusionPipeline, the file is automatically downloaded and executed during a standard DiffusionPipeline.from_pretrained() call with no additional keyword arguments. The trust_remote_code check in DiffusionPipeline.download() is bypassed because it evaluates custom_pipeline is not None as False (since the kwarg was never supplied), while the downstream code path that actually loads the module resolves the None value into a valid filename. An attacker can achieve silent arbitrary code execution by publishing a malicious model repository with a None.py file and a standard-looking model_index.json that references a legitimate pipeline class name, requiring only that a victim calls from_pretrained on the repository. This vulnerability is fixed in 0.38.0.
Affected products
-
- Version < 0.38.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Huggingface | Diffusers | n/a |
|
- < 0.38.0
No data.
Red Hat AI Inference Server 3.4
rhaii/vllm-cpu-rhel9:1789681128
Fixed · RHSA-2026:69466
Red Hat AI Inference Server 3.4
rhaii/vllm-cuda-rhel9:1789681126
Fixed · RHSA-2026:69467
Red Hat OpenShift AI 3.4
rhoai/odh-th06-cuda130-torch210-py312-rhel9:1787077779
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-th06-rocm64-torch291-py312-rhel9:1787076481
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-training-cuda128-torch29-py312-rhel9:1786611803
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-training-rocm64-torch29-py312-rhel9:1786611435
Fixed · RHSA-2026:60520
Red Hat AI Inference Server
rhaiis/vllm-rocm-rhel9
Not affected
Red Hat AI Inference Server
rhaiis/vllm-tpu-rhel9
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-aws-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-azure-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-azure-rocm-rhel9
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gcp-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-openvino-model-server-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch291-py312-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AI Inference Server 3.4 | rhaii/vllm-cpu-rhel9:1789681128 | Fixed | RHSA-2026:69466 |
| Red Hat AI Inference Server 3.4 | rhaii/vllm-cuda-rhel9:1789681126 | Fixed | RHSA-2026:69467 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-th06-cuda130-torch210-py312-rhel9:1787077779 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-th06-rocm64-torch291-py312-rhel9:1787076481 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-training-cuda128-torch29-py312-rhel9:1786611803 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-training-rocm64-torch29-py312-rhel9:1786611435 | Fixed | RHSA-2026:60520 |
| Red Hat AI Inference Server | rhaiis/vllm-rocm-rhel9 | Not affected | n/a |
| Red Hat AI Inference Server | rhaiis/vllm-tpu-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-aws-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-azure-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-azure-rocm-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gcp-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-openvino-model-server-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch291-py312-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (5)
- https://access.redhat.com/security/cve/CVE-2026-44827 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2477491 Issue Tracking
- https://github.com/huggingface/diffusers/security/advisories/GHSA-j7w6-vpvq-j3gm exploitx_refsource_CONFIRMMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-44827
- https://www.cve.org/CVERecord?id=CVE-2026-44827
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-44827 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2477491 | Issue Tracking | |
| https://github.com/huggingface/diffusers/security/advisories/GHSA-j7w6-vpvq-j3gm | exploitx_refsource_CONFIRMMitigationVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-44827 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-44827 |
Change history (0)
No recorded changes yet.