CVE-2026-65920
MEDIUMDiffusers Path Traversal via weight_map Arbitrary File Read
Title source: cnaDescription
Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or absolute paths in weight_map entries to escape the model directory and read safetensors files outside the intended location during model loading.
References (4)
Core 4
Core References
Patch patch
Patch Commit
https://github.com/huggingface/diffusers/commit/cee298c1f37c439a9a408396b8283a921238a1c6
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/diffusers-path-traversal-via-weight-map-arbitrary-file-read
Exploit technical-description
exploit
issue-tracking
Researcher Disclosure
https://github.com/huggingface/diffusers/issues/14175
Issue Tracking issue-tracking
patch
Pull Request
https://github.com/huggingface/diffusers/pull/14182
Scores
CVSS v3
4.3
EPSS
0.0032
EPSS Percentile
25.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (2)
huggingface/diffusers
< 0.39.0
huggingface/diffusers
cee298c1f37c439a9a408396b8283a921238a1c6
Published
Jul 23, 2026
Tracked Since
Jul 23, 2026