Definition

Remote code execution (or equivalent code-execution) abuse of ML dataset processing pipelines — e.g. remote-code dataset loaders and template injection in dataset configuration — used as initial access against AI platforms.

Key Points

  • AI platforms uniquely exposed where untrusted datasets trigger processing workers
  • Demonstrated in hugging-face-ai-agent-security-incident (July 2026)
  • Distinct from model-weight supply-chain poisoning; targets infra before public artifacts

Sources