CVE-2026-75104: Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitr
Summary
Hugging Face Transformers has a vulnerability where it doesn't properly check filenames in checkpoint index files (configuration files that list model components), allowing attackers to read files outside the intended model directory. An attacker can create a malicious index file with path traversal (references like '../' that escape the intended folder) or absolute paths that the software processes without validation, leading to unauthorized file access and system reconnaissance.
Vulnerability Details
5.5(medium)
EPSS: 0.0%
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
local
low
none
required
August 17, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2024-37052: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75104
First tracked: August 17, 2026 at 08:09 PM
Classified by LLM (prompt v3) · confidence: 95%