Scworld
Python Libraries in AI/ML Models Vulnerable to Metadata Poisoning
First seen 14 Jan 2026, 02:09 UTC
•
•91% similarity
•22.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Vulnerabilities have been identified in popular AI and ML Python libraries used in Hugging Face models, allowing remote attackers to embed malicious code in metadata. This code executes automatically when a file with the poisoned metadata is loaded. The affected libraries include NeMo, Uni2TS, and FlexTok, developed by Nvidia, Salesforce, and Apple in collaboration with EPFL VILAB.
ThreatCluster AI