PYSEC-2026-3804

    Dashboard / Vulnerabilities / PYSEC-2026-3804

    PYSEC-2026-3804

    Published: 10 Sept 2026Last Modified: 10 Sept 2026

    Summary: Accelerate path traversal and denial of service via sharded checkpoint weight_map entries

    Details: Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can supply relative paths with ../ sequences or absolute paths to read arbitrary files, or point shard entries at named pipes to cause indefinite blocking and denial of service.

    Affected packages

    Package

    Name: accelerate

    Purl: pkg:pypi/accelerate

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    0.0.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    PYSEC-2026-3804 | CVE-DB