Skip to content

Potential Exposure of Hugging Face Token #1

Description

@snowroll

Hello,

We are a group of security researchers conducting an analysis of publicly available resources to assess common misconfiguration risks.

During our research, we came across a Hugging Face access token exposed in a public configuration: hf_wQHI******GOcy. This token appears to be linked to your account and could potentially allow unauthorized access to Hugging Face services. If left unrevoked, it may be vulnerable to misuse.

We strongly recommend that you revoke this token immediately and generate a new one. Additionally, please review your configurations to ensure that no other sensitive credentials are publicly accessible.

If you have any questions or would like assistance in securing your environment, feel free to reach out.

Best regards,

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions