Loading
State-of-the-art diffusion in PyTorch.
Declares an LLM dependency since 2022-05-30 (version 0.0.1).
Advisories that name diffusers as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| CVE-2026-45804GHSA-7wx4-6vff-v64p: Diffusers: TOCTOU Trust Remote Code Bypass | High | < 0.38.0 | 0.38.0 | 2026-05-20 |
| CVE-2026-44513GHSA-98h9-4798-4q5v: Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components | High | < 0.38.0 | 0.38.0 | 2026-05-07 |
| GHSA-j7w6-vpvq-j3gm: Duplicate Advisory: Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components | High | < 0.38.0 | 0.38.0 | 2026-05-07 |
As declared in PyPI metadata for version 0.41.0. Optional extras are listed with their extra name.
Among the packages in the registry; not every dependent on PyPI.