- CVSS
- MEDIUM · 5.5v3.1CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Published
- 2026-08-17
- Weakness
- CWE-22
- Source
- nvd.nist.gov/vuln/detail/CVE-2026-75104
Description
Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and filesystem reconnaissance.
References
- https://github.com/huggingface/transformers
- https://github.com/huggingface/transformers/blob/main/src/transformers/utils/hub.py
- https://github.com/huggingface/transformers/issues/47176
- https://github.com/huggingface/transformers/issues/47177
- https://www.vulncheck.com/advisories/hugging-face-transformers-path-traversal-via-checkpoint-index
- https://github.com/huggingface/transformers/issues/47176
How GTK Cyber trains on this
AI security training at GTK Cyber covers the LLM and ML-pipeline vulnerability classes that vulnerabilities like CVE-2026-75104 fall into. Our hands-on courses are taught by Charles Givre and other practitioners who break and defend production AI systems.