Datasets Huggingface Datasets

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Huggingface Datasets.

By the Year

In 2026 there have been 2 vulnerabilities in Huggingface Datasets with an average score of 5.7 out of ten.

Year Vulnerabilities Average Score
2026 2 5.65

It may take a day or so for new Datasets vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Huggingface Datasets Security Vulnerabilities

Path Traversal in Hugging Face Datasets 5.0.0 via file_name
CVE-2026-66007 6.9 - Medium - July 24, 2026

Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file_name values with directory traversal sequences to read arbitrary local files, which are then embedded into output when save_to_disk or push_to_hub is called.

Directory traversal

Datasets 5.00 Symlink Extraction: Arbitrary File Write via Extractor.extract()
CVE-2026-65010 4.4 - Medium - July 23, 2026

Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-planting symlinks at predictable output paths. Attackers can redirect archive extraction to arbitrary filesystem locations in shared-cache environments, enabling overwrite of sensitive files and potential privilege escalation or code execution.

Symlink following

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Huggingface Datasets or by Huggingface? Click the Watch button to subscribe.

Huggingface
Vendor

subscribe