Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-62239

Опубликовано: 13 июл. 2026
Источник: nvd
CVSS3: 6.6
EPSS Низкий

Описание

FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filtering tar members. A local attacker can pre-plant a symlink in the predictable cache directory to redirect extracted binaries to an attacker-chosen location, enabling arbitrary file write with victim privileges during build time.

EPSS

Процентиль: 3%
0.00129
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 6.6
github
около 1 месяца назад

FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hopper/setup.py that extracts NVIDIA toolchain archives without validating symlinks or filtering tar members. A local attacker can pre-plant a symlink in the predictable cache directory to redirect extracted binaries to an attacker-chosen location, enabling arbitrary file write with victim privileges during build time.

EPSS

Процентиль: 3%
0.00129
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-59