Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-75104

Опубликовано: 17 авг. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and filesystem reconnaissance.

A flaw was found in Hugging Face Transformers. Attackers can exploit this by supplying malicious checkpoint index files with parent-directory references or absolute paths that are not properly validated. This vulnerability allows for reading arbitrary files outside the model directory, leading to information disclosure and filesystem reconnaissance.

Отчет

A flaw was found in Hugging Face Transformers in the handling of checkpoint index files. The library fails to properly validate shard filenames, allowing attackers to supply malicious checkpoint index files containing parent-directory references or absolute paths. When a user processes such a malicious checkpoint file, the path traversal vulnerability allows reading arbitrary files outside the intended model directory. This can lead to information disclosure and filesystem reconnaissance. Exploitation requires local access and user interaction to process the malicious checkpoint file.

Меры по смягчению последствий

Upgrade to a fixed version of Hugging Face Transformers when available (currently affected versions: <= 5.15.0). As a workaround, only load checkpoint files from trusted sources, implement additional validation of checkpoint index file paths before processing, and run AI/ML workloads in sandboxed environments with restricted file system access to limit the impact of arbitrary file reads.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/model-opt-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/model-opt-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2517610transformers: Hugging Face Transformers: Information Disclosure via Path Traversal in Checkpoint Index

EPSS

Процентиль: 9%
0.0019
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
около 1 месяца назад

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and filesystem reconnaissance.

CVSS3: 5.5
github
около 1 месяца назад

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and filesystem reconnaissance.

EPSS

Процентиль: 9%
0.0019
Низкий

5.5 Medium

CVSS3