VYPR
Medium severity6.6OSV Advisory· Published Jul 23, 2026· Updated Jul 23, 2026

CVE-2026-65010

CVE-2026-65010

Description

Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-planting symlinks at predictable output paths. Attackers can redirect archive extraction to arbitrary filesystem locations in shared-cache environments, enabling overwrite of sensitive files and potential privilege escalation or code execution.

Affected products

2
  • Huggingface/Datasetsllm-fuzzy2 versions
    <=5.00+ 1 more
    • (no CPE)range: <=5.00
    • (no CPE)range: 5.0.0, 4.8.5, 4.8.4, …

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.