PT-2026-64320 · Hugging Face · Datasets
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file name values with directory traversal sequences to read arbitrary local files, which are then embedded into output when save to disk or push to hub is called.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datasets