What is CVE-2026-69112?
CVE-2026-69112 is a path traversal vulnerability in Hugging Face Accelerate up to version 1.14.0, affecting the load_checkpoint_in_model and load_checkpoint_and_dispatch functions. Due to insufficient sanitization of weight_map entries in sharded checkpoint indexes, attackers can use relative paths like ../ to read or write arbitrary files. Users should upgrade to the latest patched version and avoid untrusted checkpoint sources.
Azərbaycanca: CVE-2026-69112 Hugging Face Accelerate kitabxanasının 1.14.0 versiyasına qədər olan versiyalarında `load_checkpoint_in_model` və `load_checkpoint_and_dispatch` funksiyalarında path traversal zəifliyidir. `weight_map` daxilində `../` kimi nisbi yolların yoxlanılmaması səbəbindən, uzaqdan hücum edən şəxs fayl sistemində ixtiyari fayl yazmaq və ya oxumaq imkanı əldə edə bilər. İstifadəçilərə kitabxananı ən son versiyaya yeniləmək və şübhəli checkpoint mənbələrindən istifadə etməmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Hugging Face
FAQ2
Which library is affected by CVE-2026-69112?
CVE-2026-69112 affects the Hugging Face Accelerate library.
What is recommended to mitigate CVE-2026-69112?
Users are advised to upgrade to the latest patched version and avoid untrusted checkpoint sources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.