Количество 3
Количество 3
CVE-2026-65920
A flaw was found in Diffusers. This path traversal vulnerability in the `_get_checkpoint_shard_files` function allows a remote attacker to read arbitrary files. By supplying malicious `weight_map` values in model index JSON, an attacker can use `../` sequences or absolute paths to escape the model directory and read sensitive files outside the intended location during model loading. This could lead to information disclosure.
CVE-2026-65920
Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or absolute paths in weight_map entries to escape the model directory and read safetensors files outside the intended location during model loading.
GHSA-9576-hw58-7552
Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or absolute paths in weight_map entries to escape the model directory and read safetensors files outside the intended location during model loading.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-65920 A flaw was found in Diffusers. This path traversal vulnerability in the `_get_checkpoint_shard_files` function allows a remote attacker to read arbitrary files. By supplying malicious `weight_map` values in model index JSON, an attacker can use `../` sequences or absolute paths to escape the model directory and read sensitive files outside the intended location during model loading. This could lead to information disclosure. | CVSS3: 4.3 | 0% Низкий | 9 дней назад | |
CVE-2026-65920 Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or absolute paths in weight_map entries to escape the model directory and read safetensors files outside the intended location during model loading. | CVSS3: 4.3 | 0% Низкий | 9 дней назад | |
GHSA-9576-hw58-7552 Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or absolute paths in weight_map entries to escape the model directory and read safetensors files outside the intended location during model loading. | CVSS3: 4.3 | 0% Низкий | 9 дней назад |
Уязвимостей на страницу