PT-2026-64148 · Hugging Face · Datasets

·

CVE-2026-65010

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-planting symlinks at predictable output paths. Attackers can redirect archive extraction to arbitrary filesystem locations in shared-cache environments, enabling overwrite of sensitive files and potential privilege escalation or code execution.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65010

Affected Products

Datasets