Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because download() validates model_index.json and custom pipeline code before later loading from a cached folder that can change, allowing a Hub repository with custom .py pipeline code to execute through the custom pipeline flow without passing custom_pipeline or trust_remote_code=True. This issue is fixed in version 0.38.0.
The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Diffusers | Huggingface | * | 0.38.0 (excluding) |
| Red Hat AI Inference Server 3.4 | RedHat | rhaii/vllm-cpu-rhel9:1789681128 | * |
| Red Hat AI Inference Server 3.4 | RedHat | rhaii/vllm-cuda-rhel9:1789681126 | * |
| Red Hat OpenShift AI 3.4 | RedHat | rhoai/odh-th06-cuda130-torch210-py312-rhel9:1787077779 | * |
| Red Hat OpenShift AI 3.4 | RedHat | rhoai/odh-th06-rocm64-torch291-py312-rhel9:1787076481 | * |
| Red Hat OpenShift AI 3.4 | RedHat | rhoai/odh-training-cuda128-torch29-py312-rhel9:1786611803 | * |
| Red Hat OpenShift AI 3.4 | RedHat | rhoai/odh-training-rocm64-torch29-py312-rhel9:1786611435 | * |