🟠 High  |  Source: The Register — Security


Security researchers at JFrog appear to have discovered zero-day vulnerabilities that could allow AI models hosted on OpenAI’s platform to compromise Hugging Face infrastructure, though JFrog has not publicly confirmed or denied the findings. The potential impact is significant given Hugging Face’s role as a central repository for machine learning models used across the industry. If confirmed, this would represent a serious supply chain risk, as malicious activity originating from AI models could propagate to downstream users and organisations.

Security Architect’s Take: Audit any pipelines that pull models or artefacts from Hugging Face and apply strict integrity verification — cryptographic checksums and provenance attestation at minimum. Until JFrog and Hugging Face issue official guidance, treat third-party model sources as untrusted and review sandbox isolation for any AI inference workloads in your environment.

Original advisory: Looks like JFrog’s 0-days let OpenAI’s models hack Hugging Face