What is CVE-2026-65010?
CVE-2026-65010 is a symlink-following vulnerability in the `Extractor.extract()` function of the `Datasets` library up to version 5.00. Local attackers can write arbitrary files by pre-planting symlinks at predictable output paths, redirecting archive extraction to unintended filesystem locations. It is recommended to update to the version containing the `ad2d853` fix commit.
Azərbaycanca: CVE-2026-65010 `Datasets` kitabxanasının 5.00-ə qədər versiyalarında `Extractor.extract()` funksiyasında simvolik keçid `symlink` izləmə zəifliyidir. Yerli təcavüzkarlar proqnozlaşdırıla bilən çıxış yollarında əvvəlcədən yerləşdirilmiş simvolik keçidlər vasitəsilə arxiv açma prosesini manipulyasiya edərək ixtiyari faylları yaza bilərlər. Bu problemi aradan qaldırmaq üçün `ad2d853` commit-i ilə düzəldilmiş versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which library and function are affected by CVE-2026-65010?
CVE-2026-65010 is a symlink-following vulnerability in the `Extractor.extract()` function of the `Datasets` library up to version 5.00.
What is the recommended action to fix this security issue?
It is recommended to update to the version containing the `ad2d853` fix commit.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.