漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Diffusers: TOCTOU Trust Remote Code Bypass
Vulnerability Description
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change, allowing a Hub repository with custom .py pipeline code to execute through the custom pipeline flow without passing custom_pipeline or trust_remote_code=True. This issue is fixed in version 0.38.0.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Vulnerability Title
huggingface diffusers 竞争条件问题漏洞
Vulnerability Description
huggingface diffusers是huggingface的机器学习工具。 huggingface diffusers 0.38.0之前版本存在竞争条件问题漏洞,该漏洞源于DiffusionPipeline.from_pretrained流程可以绕过trust_remote_code防护,因为download()在验证model_index.json和自定义pipeline代码后,从可能变化的缓存文件夹加载,允许具有自定义.py pipeline代码的Hub仓库通过自定义pipeline流程执行,
CVSS Information
N/A
Vulnerability Type
N/A