Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
Summary
Hugging Face, a platform hosting AI models and datasets, disclosed that attackers exploited a security vulnerability to run malicious code on its servers, compromising internal datasets and service credentials (codes that prove identity and grant access to systems). The company has fixed the vulnerability and revoked the stolen credentials, while urging users to rotate their own keys and review account activity for suspicious behavior.
Solution / Mitigation
According to the source, Hugging Face has taken these steps: (1) revoked and rotated the stolen credentials that were accessed, (2) fixed the vulnerability that was abused during the cyberattack, and (3) urged users to 'do the same with any keys stored on the platform, and review any suspicious activity on their accounts.' The company also reported the incident to law enforcement and engaged cybersecurity forensic specialists to investigate.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://techcrunch.com/2026/07/20/hugging-face-confirms-breach-affected-internal-datasets-and-credentials-urges-users-to-take-action/
First tracked: July 20, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%