
CVE-2026-69112: path traversal in Hugging Face Accelerate (through 1.14.0). Malicious sharded checkpoint indexes can read arbitrary files via weight_map paths, or hang loaders via named pipes. 27M monthly downloads exposed. No patch yet. Validation code inside: https://hol.org/blog/cve-2026-69112-hugging-face-accelerate-path-traversal
Post summary
CVE-2026-69112 exposes a path‑traversal flaw in Hugging Face Accelerate 1.14.0, allowing arbitrary file reads through malicious checkpoint indexes, with validation code provided but no patch yet.
