Hugging Face Transformers Path Traversal via Checkpoint Index
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.8epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and filesystem reconnaissance.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
huggingface · transformersReferences
https://github.com/huggingface/transformershttps://github.com/huggingface/transformers/blob/main/src/transformers/utils/hub.pyhttps://github.com/huggingface/transformers/issues/47176https://github.com/huggingface/transformers/issues/47177https://www.vulncheck.com/advisories/hugging-face-transformers-path-traversal-via-checkpoint-index