{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/accelerate-1.14.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-69112"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Accelerate (1.14.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","python"],"_cs_type":"advisory","_cs_vendors":["Hugging Face"],"content_html":"\u003cp\u003eHugging Face Accelerate versions up to and including 1.14.0 are affected by a path traversal vulnerability residing within the \u003ccode\u003eload_checkpoint_in_model\u003c/code\u003e and \u003ccode\u003eload_checkpoint_and_dispatch\u003c/code\u003e functions. The vulnerability arises because the library fails to properly sanitize the \u003ccode\u003eweight_map\u003c/code\u003e entries contained within sharded checkpoint index files.\u003c/p\u003e\n\u003cp\u003eAn attacker capable of providing a malicious checkpoint index can use relative path sequences such as \u003ccode\u003e../\u003c/code\u003e or absolute file paths to force the application to read files outside of the intended directory. Furthermore, by pointing a shard entry at a system named pipe, an attacker can trigger indefinite blocking of the process, resulting in a denial of service. This vulnerability poses a significant risk to environments where model checkpoints are sourced from untrusted or external contributors.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized actors to read arbitrary files from the host system, potentially exposing sensitive configuration files, credentials, or other model data. Additionally, the ability to induce a denial of service via named pipes impacts the availability of machine learning inference or training workloads utilizing the affected library.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Hugging Face Accelerate to the latest patched version immediately.\u003c/li\u003e\n\u003cli\u003eImplement strict validation of all externally sourced model checkpoint index files before processing them with Accelerate.\u003c/li\u003e\n\u003cli\u003eRun model training and inference workloads in isolated, containerized environments with restricted filesystem permissions and read-only access to non-essential directories to limit the impact of path traversal.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T01:37:01Z","date_published":"2026-08-11T01:37:01Z","id":"https://feed.craftedsignal.io/briefs/2026-08-accelerate-traversal/","summary":"Hugging Face Accelerate versions 1.14.0 and earlier contain a path traversal vulnerability in checkpoint loading functions that allows arbitrary file reads or denial of service via named pipes.","title":"Path Traversal Vulnerability in Hugging Face Accelerate","url":"https://feed.craftedsignal.io/briefs/2026-08-accelerate-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Accelerate (1.14.0)","version":"https://jsonfeed.org/version/1.1"}