Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cve-2026-75104'

View all threats tagged with 'cve-2026-75104'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-75104

Threats Tagged 'cve-2026-75104'

Click on any threat for detailed analysis and mitigation recommendations

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model… (CVE-2026-75104)CVE-2026-75104
0

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and filesystem reconnaissance.

Join the discussion
CVE-2026-75104: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in huggingface transformersCVE-2026-75104
0

CVE-2026-75104 is a path traversal vulnerability in Hugging Face Transformers that allows attackers to read arbitrary files outside the intended model directory. This occurs because shard filenames in checkpoint index files are not properly validated, enabling malicious index files with parent-directory references or absolute paths to disclose files and perform filesystem reconnaissance. The vulnerability affects versions up to and including 5.15.0. The CVSS 4.0 score is 6.8, indicating a medium severity. No official patch or remediation guidance is currently available.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-75104
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses