<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — Hugging Face</title><description>Articles on devtake.dev covering Hugging Face.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>A malicious GGUF file owns your SGLang server: CVE-2026-5760 is an unpatched 9.8</title><link>https://devtake.dev/article/sglang-cve-2026-5760-gguf-rce/</link><guid isPermaLink="true">https://devtake.dev/article/sglang-cve-2026-5760-gguf-rce/</guid><description>SGLang&apos;s reranker renders chat templates without a sandbox. Load a hostile GGUF, hit /v1/rerank, and the attacker has Python on your inference box. No patch yet.</description><pubDate>Mon, 27 Apr 2026 11:30:00 GMT</pubDate><category>security</category><category>sglang</category><category>cve-2026-5760</category><category>supply-chain</category><category>ai-security</category><category>llm</category><category>rce</category><category>jinja2</category><category>gguf</category><author>luca-reinhardt</author></item><item><title>OpenAI&apos;s Privacy Filter is a 1.5B PII redactor that ships under Apache 2.0. Here&apos;s what it actually does.</title><link>https://devtake.dev/article/openai-privacy-filter/</link><guid isPermaLink="true">https://devtake.dev/article/openai-privacy-filter/</guid><description>OpenAI released Privacy Filter on April 22 as an open-weight on-device model for masking eight types of PII. F1 of 96%. Runs in a browser. Here&apos;s the catch.</description><pubDate>Sun, 26 Apr 2026 13:00:00 GMT</pubDate><category>ai</category><category>openai</category><category>privacy</category><category>pii</category><category>open-weights</category><category>ai-models</category><category>llm</category><category>hugging-face</category><category>data-privacy</category><author>dieter-morelli</author></item></channel></rss>