Threats Tagged 'cve-2026-75104'
View all threats tagged with 'cve-2026-75104'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-75104'
Click on any threat for detailed analysis and mitigation recommendations
Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model… (CVE-2026-75104)CVE-2026-75104 0 Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and filesystem reconnaissance. Join the discussion | GCVE Database | 08/17/2026, 21:31:26 UTC Added: 08/17/2026, 22:33:24 UTC |
CVE-2026-75104: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in huggingface transformersCVE-2026-75104 0 CVE-2026-75104 is a path traversal vulnerability in Hugging Face Transformers that allows attackers to read arbitrary files outside the intended model directory. This occurs because shard filenames in checkpoint index files are not properly validated, enabling malicious index files with parent-directory references or absolute paths to disclose files and perform filesystem reconnaissance. The vulnerability affects versions up to and including 5.15.0. The CVSS 4.0 score is 6.8, indicating a medium severity. No official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 08/17/2026, 20:36:00 UTC Added: 08/17/2026, 20:42:01 UTC |
Showing 1 to 2 of 2 results