AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-66007.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 6.9CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 02, 2026

Disclosure summary

Datasets through 5.0.0, fixed in f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file_name values with directory traversal sequences to read arbitrary local files, which are then embedded into output when save_to_disk or push_to_hub is called.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-379c-qx7v-6h59

Open original source · Updated Oct 02, 2026

Hugging Face Datasets folder-based builders allow path traversal through file_name metadata

Source severity: MEDIUM / 6.9

EcosystemPackageAffected rangeFirst patched
pipdatasets< 5.0.15.0.1

Original records & references

PUBLISHED 2026-07-24T11:33:03-04:00
MODIFIED 2026-10-02T18:43:38-04:00
INGESTED 2026-10-06T11:45:17-04:00