Back

MEDIUM

Hugging Face Accelerate 1.14.0 Path Traversal and DoS via weight_map

Published Aug 10, 2026

Description

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can supply relative paths with ../ sequences or absolute paths to read arbitrary files, or point shard entries at named pipes to cause indefinite blocking and denial of service.

Affected products

Remediation

Red Hat statement

This is an Important vulnerability in Hugging Face Accelerate that could lead to arbitrary file disclosure and denial of service. While requiring user interaction, an attacker could craft malicious `weight_map` entries in sharded checkpoint indexes to exploit path traversal, impacting the confidentiality and availability of systems utilizing affected Red Hat AI/ML products.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 10, 2026
Updated Aug 11, 2026
Reserved Aug 3, 2026
CISA Vulnrichment
Updated Aug 11, 2026
NVD
Status Awaiting Analysis
Modified Sep 16, 2026
Red Hat
Severity Important
Public date Aug 10, 2026
ENISA EUVD
Assigner VulnCheck
Published Aug 10, 2026
Updated Aug 11, 2026
Exploited since n/a
EUVD-2026-55743 GHSA-4J2P-28Q2-5M79