Quoting huggingface.co/security.txt
Summary
Hugging Face's security.txt file contains a message directed at AI agents, discouraging them from attempting to find vulnerabilities on Hugging Face's systems by pointing them instead toward the publicly available CyberGym benchmark (a testing environment for security challenges) on GitHub as a legitimate alternative.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2024-37052: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling
Original source: https://simonwillison.net/2026/Sep/11/hugging-face-security/
First tracked: September 11, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 70%