CVE-2026-69112: Huggingface Accelerate

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_checkpoint_and_dispatch functions that fail to sanitize weight_map entries from sharded checkpoint indexes. Attackers can supply relative paths with ../ sequences or absolute paths to read arbitrary files, or point shard entries at named pipes to cause indefinite blocking and denial of service.

Affected products

Published 2026-08-10. Last modified 2026-09-16.