Lemma Critical Brief · Category archive
Model Supply Chain
Poisoned model weights, backdoored checkpoints, evaluation-data contamination.
6 Briefs
"FaceHugger" in Hugging Face Diffusers: loading a model ran arbitrary code
the safeguard only checked the first fetch (Zafran / CVE-2026-44827 et al.)
A fake OpenAI model hit #1 trending on Hugging Face
publisher provenance never verified before execution
AIR: A Fake Agent Skill Cleared Every Scanner and Reached ~26,000 Agents
the Blind Spot Was an External Link Mutable After the Scan
Hugging Face LeRobot: a robotics framework executed untrusted data received over an unauthenticated channel
deserializing (pickle) unverified data leads straight to code execution (CVE-2026-25874)
ShadowMQ: one unsafe pattern (unauthenticated ZMQ + pickle) copied across AI inference frameworks
the same flaw spread at ecosystem scale through reuse (Oligo Security)