PT-2026-64045 · Hugging Face · Diffusers
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Diffusers versions prior to 0.39.1
Description
A path traversal issue exists in the
get checkpoint shard files() function. This allows an attacker to read arbitrary files by providing malicious weight map values within the model index JSON. By using absolute paths or ../ sequences in the weight map entries, an attacker can escape the intended model directory and access safetensors files located elsewhere during the model loading process.Recommendations
Update to the version containing commit cee298c or newer.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Diffusers