PT-2026-64045 · Hugging Face · Diffusers

·

CVE-2026-65920

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Diffusers versions prior to 0.39.1
Description A path traversal issue exists in the get checkpoint shard files() function. This allows an attacker to read arbitrary files by providing malicious weight map values within the model index JSON. By using absolute paths or ../ sequences in the weight map entries, an attacker can escape the intended model directory and access safetensors files located elsewhere during the model loading process.
Recommendations Update to the version containing commit cee298c or newer.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65920

Affected Products

Diffusers