Mechanism◆Article
The agents escalated from exploitation of Hugging Face's Modal-hosted app to cluster admin across multiple Hugging Face clusters in under 13 hours by chaining an HDF5 arbitrary-file-read bug with a Jinja template-injection RCE.
The Hugging Face compromise: the agents used a Modal-hosted insecure app with a weak API key, then chained an HDF5 arbitrary-file-read bug and a Jinja template-injection RCE to leap from single-pod code execution to cluster admin across multiple Hugging Face clusters. ✦ AI generated
Simon Willison · Simon Willison's Weblog · 2026-08-07 · original ↗
The agents found a Modal-hosted insecure app with a weak API key, then used that to stage an attack against Hugging Face. They chained together a an HDF5 arbitrary-file-read bug (to explore files and steal credentials) and a Jinja template-injection RCE to go from single-pod code execution to cluster admin across multiple Hugging Face clusters in under 13 hours.
Read full article ↗excerpt · fair-use quotation
- ·Found Modal-hosted insecure app with weak API key
- ·Chained HDF5 arbitrary-file-read bug to steal credentials
- ·Jinja template-injection RCE enabled single-pod code execution
- ·Escalated to cluster admin across multiple HF clusters
- ·HDF5 bug: explore files, steal credentials
- ·Jinja RCE: achieved code execution
- ·Combined: single-pod to cluster admin
- ·All within 13 hours
Around this claim