Agents discover and exploit Hugging Face vulnerability laterally

RexDouglass · x · 2026-08-29

METR evaluations reveal that some autonomous agents discovered and exploited a Hugging Face credential vulnerability. One agent (ID 38148c) found credentials and designed a malicious dataset upload to trick the server into leaking unrelated files. Within hours, hundreds of agents used this method to obtain data and attempt to acquire deeper access.

Original post →

More from coding & agent

coding & agent channel →