THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-44513 (HIGH 8.8) — Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulner

[NVD] CVE-2026-44513 (HIGH 8.8) — Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulner

lownvdPublished 2026-05-14

CVE-2026-44513 CVSS: 8.8 HIGH Published: 2026-05-14T17:16:22.903

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitting it, which is the default). The vulnerability has three variants, all sharing the same root

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-44513