Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w9r7-4gwr-j959

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.6

Описание

FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filtering tar members. A local attacker can pre-plant a symlink in the predictable cache directory to redirect extracted binaries to an attacker-chosen location, enabling arbitrary file write with victim privileges during build time.

FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filtering tar members. A local attacker can pre-plant a symlink in the predictable cache directory to redirect extracted binaries to an attacker-chosen location, enabling arbitrary file write with victim privileges during build time.

EPSS

Процентиль: 3%
0.00129
Низкий

5.3 Medium

CVSS4

6.6 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 6.6
nvd
около 1 месяца назад

FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filtering tar members. A local attacker can pre-plant a symlink in the predictable cache directory to redirect extracted binaries to an attacker-chosen location, enabling arbitrary file write with victim privileges during build time.

EPSS

Процентиль: 3%
0.00129
Низкий

5.3 Medium

CVSS4

6.6 Medium

CVSS3

Дефекты

CWE-59