Hugging Face confirms breach affected internal datasets and credentials, urges users to take action

Hugging Face has confirmed a security breach where attackers exploited a vulnerability in a hosted dataset to gain unauthorized access to internal systems. The company has since patched the vulnerability and rotated compromised credentials, urging users to review their own account security.
Why it matters
As a central hub for open-source AI development, a compromise at Hugging Face poses significant risks to the integrity of AI models and the security of the broader developer ecosystem.
Hugging Face, a platform that hosts AI models and datasets , said its internal datasets and service credentials were compromised in a hack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident.
In a blog post , the company said a dataset uploaded to its platform abused a security vulnerability to run malicious code on its servers, allowing the attackers to escalate their permissions and gain broader access to Hugging Face’s internal systems.
The company said it has revoked and rotated the stolen credentials that were accessed. It urged users to do the same with any keys stored on the platform, and review any suspicious activity on their accounts.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in