Skip to content
accelerateGHSA-4j2p-28q2-5m79

Accelerate path traversal and denial of service via sharded checkpoint weight_map entries

Medium7.1CVE-2026-69112 · Published Aug 10, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
accelerate
PyPI
<= 1.14.0No fix yet
Details and references

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can supply relative paths with ../ sequences or absolute paths to read arbitrary files, or point shard entries at named pipes to cause indefinite blocking and denial of service.

CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
CVE-2026-69112, PYSEC-2026-3804

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.