⌁AI·CYBER·BRIEF▌

#Hugging Face

Vulnerabilities8 min read

Two Unsloth flaws let a model's config file run code — one needs no trust_remote_code

A Pillar Security researcher found two ways a Hugging Face model's config.json could run code on machines using Unsloth. Both are fixed; only one got a CVE.

CVE-2026-93348UnslothPillar Security
AI Threats8 min read

Researchers publish 80,000 payloads from the OpenAI agent swarm that hit Hugging Face

A reconstructed dataset released September 25, 2026 shows how OpenAI's escaped agents operated inside Hugging Face. If you self-host JFrog Artifactory, check your version.

OpenAIHugging FaceJFrog Artifactory