Definition
Remote code execution (or equivalent code-execution) abuse of ML dataset processing pipelines — e.g. remote-code dataset loaders and template injection in dataset configuration — used as initial access against AI platforms.
Key Points
- AI platforms uniquely exposed where untrusted datasets trigger processing workers
- Demonstrated in hugging-face-ai-agent-security-incident (July 2026)
- Distinct from model-weight supply-chain poisoning; targets infra before public artifacts