Intel

AIKIDO-2026-37276

huggingface-hub is vulnerable to Improper Authentication

Improper Authentication Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 5 days ago

59

Medium Risk

This Affects:

PYTHONhuggingface-hub
1.22.0 - 1.31.0
Fixed in 1.32.0
Are you affected? Scan for Free

TL;DR

Pooled SandboxPool hosts in huggingface-hub used one job wide X-Sandbox-Token for every sandbox on a host, and proxy_headers passed that host credential to browsers or WebSocket clients. Discovered hosts were taken from Job labels without binding initiator, image, flavor, command, or URL, and the local pool cache was keyed only by pool id, so Hub credentialed requests could go to a spoofed or cross context host. A leaked or misdelivered host token authorized every current and future sandbox on that host, including pool management. The fix mints a random per sandbox capability token for pooled operations, checks discovered hosts before sending credentials, and keys the cache by endpoint, credential, and namespace.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use pooled Hub sandboxes.

Background info

huggingface-hub is vulnerable to Improper Authentication in versions 1.22.0 - 1.31.0.

How to fix this

Upgrade the huggingface-hub library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform