Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or absolute paths in weight_map entries to escape the model directory and read safetensors files outside the intended location during model loading.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or absolute paths in weight_map entries to escape the model directory and read safetensors files outside the intended location during model loading. | |
| Title | Diffusers Path Traversal via weight_map Arbitrary File Read | |
| First Time appeared |
Huggingface
Huggingface diffusers |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:huggingface:diffusers:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Huggingface
Huggingface diffusers |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-23T18:19:21.917Z
Reserved: 2026-07-23T12:51:09.596Z
Link: CVE-2026-65920
Updated: 2026-07-23T18:19:18.348Z
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses