Описание
Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and filesystem reconnaissance.
A flaw was found in Hugging Face Transformers. Attackers can exploit this by supplying malicious checkpoint index files with parent-directory references or absolute paths that are not properly validated. This vulnerability allows for reading arbitrary files outside the model directory, leading to information disclosure and filesystem reconnaissance.
Отчет
A flaw was found in Hugging Face Transformers in the handling of checkpoint index files. The library fails to properly validate shard filenames, allowing attackers to supply malicious checkpoint index files containing parent-directory references or absolute paths. When a user processes such a malicious checkpoint file, the path traversal vulnerability allows reading arbitrary files outside the intended model directory. This can lead to information disclosure and filesystem reconnaissance. Exploitation requires local access and user interaction to process the malicious checkpoint file.
Меры по смягчению последствий
Upgrade to a fixed version of Hugging Face Transformers when available (currently affected versions: <= 5.15.0). As a workaround, only load checkpoint files from trusted sources, implement additional validation of checkpoint index file paths before processing, and run AI/ML workloads in sandboxed environments with restricted file system access to limit the impact of arbitrary file reads.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Lightspeed Core | lightspeed-core/lightspeed-stack-rhel9 | Fix deferred | ||
| Lightspeed Core | lightspeed-core/rag-tool-cpu-rhel9 | Fix deferred | ||
| Lightspeed Core | lightspeed-core/rag-tool-cuda-12.9-rhel9 | Fix deferred | ||
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-ocp-rag-rhel9 | Fix deferred | ||
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-service-api-rhel9 | Fix deferred | ||
| OpenShift Lightspeed | openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9 | Fix deferred | ||
| Red Hat AI Inference Server | rhaii/model-opt-cuda-rhel9 | Fix deferred | ||
| Red Hat AI Inference Server | rhaiis/model-opt-cuda-rhel9 | Fix deferred | ||
| Red Hat AI Inference Server | rhaiis/vllm-cpu-rhel9 | Fix deferred | ||
| Red Hat AI Inference Server | rhaiis/vllm-cuda-rhel9 | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and filesystem reconnaissance.
Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and filesystem reconnaissance.
EPSS
5.5 Medium
CVSS3