PyPi: Huggingface-Hub

PVE-2023-54919

Safety vulnerability ID: 54919

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Apr 06, 2023 Updated at Oct 28, 2024

Advisory

Huggingface-hub 0.13.4 includes a security fix: Malicious repo can overwrite any file on …

[This advisory has been limited. Please create a free account to view the full advisory.]

Affected package

huggingface-hub

Latest version: 0.26.2

Client library to download and publish models, datasets and other repos on the huggingface.co hub

Affected versions

Fixed versions

Vulnerability changelog

Security patch to fix a vulnerability in `huggingface_hub`. In some cases, downloading a …

[This text has been limited. Please create a free account to view the full text.]

Resources